Introduction of a Tool-based Continuous Information Security Management System: An Exploratory Case Study

被引:8
|
作者
Brunner, Michael [1 ]
Mussmann, Andrea [1 ]
Breu, Ruth [1 ]
机构
[1] Univ Innsbruck, Inst Comp Sci, Innsbruck, Austria
关键词
Information Security Management System; Information Security Risk Management; Process Improvement; Case Study;
D O I
10.1109/QRS-C.2018.00088
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Tighter regulatory demands and higher customer expectations regarding the protection of information force enterprises to systematically ensure confidentiality, integrity and availability of stored information and processing facilities. Information Security Management Systems (ISMSs) are used to address these challenges. Recent studies show that the majority of companies plans to establish at least basic information security management to prepare for future developments. Larger enterprises have already embraced ISMSs, whereas small and medium-sized enterprises (SMEs) are catching up and require support in defining, introducing and operating them. We developed ADAMANT, an SME-friendly tool that supports continuous information security management incorporating stakeholders of different domains. In this paper, we evaluated our approach to introduce an ISMS in SMEs using an introductory information security training. The evaluation shows that our tool improves critical information security management tasks. Furthermore, integrating ADAMANT in customized security trainings allows companies to directly use training results to implement an ISMS.
引用
收藏
页码:483 / 490
页数:8
相关论文
共 50 条
  • [1] Tool-based Interaction for Precise Manipulation in VR: an Exploratory Study
    Geurts, Eva
    Van den Bergh, Jan
    Vanherle, Bram
    [J]. PROCEEDINGS OF THE EUROPEAN CONFERENCE ON COGNITIVE ERGONOMICS, ECCE 2023: Responsible Technology Community, Culture, and Sustainability, 2023,
  • [2] The Management of IT Security with a Continuous Security Monitoring System - A Case Study
    Tinca, Andrei
    [J]. METALURGIA INTERNATIONAL, 2013, 18 : 22 - 27
  • [3] A TOOL-BASED SYSTEM ARCHITECTURE FOR A DIGITAL TWIN: A CASE STUDY IN A HEALTHCARE FACILITY
    Harode, Ashit
    Thabet, Walid
    Jamerson, W.E.
    Dongre, Poorvesh
    [J]. Journal of Information Technology in Construction, 2023, 28 : 107 - 137
  • [4] A TOOL-BASED SYSTEM ARCHITECTURE FOR A DIGITAL TWIN: A CASE STUDY IN A HEALTHCARE FACILITY
    Harode, Ashit
    Thabet, Walid
    Dongre, Poorvesh
    [J]. JOURNAL OF INFORMATION TECHNOLOGY IN CONSTRUCTION, 2023, 28 : 107 - 137
  • [5] Tool-based Interactive Software Parallelization: A Case Study
    Wilhelm, Andreas
    Cakaric, Faris
    Gerndt, Michael
    Schuele, Tobias
    [J]. 2018 IEEE/ACM 40TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING - SOFTWARE ENGINEERING IN PRACTICE TRACK (ICSE-SEIP 2018), 2018, : 115 - 123
  • [6] INTEGRATION REQUIREMENTS FOR TOOL-BASED GENERATION OF INFORMATION-SYSTEM DOCUMENTATION
    VERRIJNSTUART, AA
    [J]. BUSINESS PROCESS RE-ENGINEERING: INFORMATION SYSTEMS OPPORTUNITIES AND CHALLENGES, 1994, 54 : 593 - 602
  • [7] Timed sequence diagrams and tool-based analysis - A case study
    Firley, T
    Huhn, M
    Diether, K
    Gehrke, T
    Goltz, U
    [J]. UML'99 - THE UNIFIED MODELING LANGUAGE: BEYOND THE STANDARD, 1999, 1723 : 645 - 660
  • [8] A Tool-based Semantic Framework for Security Requirements Specification
    Daramola, Olawande
    Sindre, Guttorm
    Moser, Thomas
    [J]. JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2013, 19 (13) : 1940 - 1962
  • [9] Tool-based risk management made practical
    Doernemann, H
    [J]. IEEE JOINT INTERNATIONAL CONFERENCE ON REQUIREMENTS ENGINEERING, PROCEEDINGS, 2002, : 192 - 192
  • [10] Tool-based renewable energy system planning using survey data: A case study in rural Vietnam
    Hart, Maria C. G.
    Eckhoff, Sarah
    Breitner, Michael H.
    [J]. ENVIRONMENT DEVELOPMENT AND SUSTAINABILITY, 2024, 26 (04) : 9817 - 9845