Introduction of a Tool-based Continuous Information Security Management System: An Exploratory Case Study

被引:8
|
作者
Brunner, Michael [1 ]
Mussmann, Andrea [1 ]
Breu, Ruth [1 ]
机构
[1] Univ Innsbruck, Inst Comp Sci, Innsbruck, Austria
关键词
Information Security Management System; Information Security Risk Management; Process Improvement; Case Study;
D O I
10.1109/QRS-C.2018.00088
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Tighter regulatory demands and higher customer expectations regarding the protection of information force enterprises to systematically ensure confidentiality, integrity and availability of stored information and processing facilities. Information Security Management Systems (ISMSs) are used to address these challenges. Recent studies show that the majority of companies plans to establish at least basic information security management to prepare for future developments. Larger enterprises have already embraced ISMSs, whereas small and medium-sized enterprises (SMEs) are catching up and require support in defining, introducing and operating them. We developed ADAMANT, an SME-friendly tool that supports continuous information security management incorporating stakeholders of different domains. In this paper, we evaluated our approach to introduce an ISMS in SMEs using an introductory information security training. The evaluation shows that our tool improves critical information security management tasks. Furthermore, integrating ADAMANT in customized security trainings allows companies to directly use training results to implement an ISMS.
引用
收藏
页码:483 / 490
页数:8
相关论文
共 50 条
  • [41] An enhanced smartphone security model based on information security management system (ISMS)
    Park, Jong Hyuk
    Yi, Ki Jung
    Jeong, Young-Sik
    [J]. ELECTRONIC COMMERCE RESEARCH, 2014, 14 (03) : 321 - 348
  • [42] An enhanced smartphone security model based on information security management system (ISMS)
    Jong Hyuk Park
    Ki Jung Yi
    Young-Sik Jeong
    [J]. Electronic Commerce Research, 2014, 14 : 321 - 348
  • [43] Information Security Management: A Case Study in a Portuguese Military Organization
    Martins, Jose
    dos Santos, Henrique
    Rosinha, Antonio
    Valente, Agostinho
    [J]. INTERNATIONAL JOURNAL OF CYBER WARFARE AND TERRORISM, 2013, 3 (03) : 32 - 48
  • [44] Integrated Implementation of Service and Information Security Management System (case study: State Polytehnic of Lampung)
    Putra, Septafiansyah Dwi
    Sutikno, Sarwono
    Rosmansyah, Yusep
    Asrowardi, Imam
    [J]. 2014 INTERNATIONAL CONFERENCE ON ICT FOR SMART SOCIETY (ICISS), 2014, : 185 - 191
  • [45] The Use of an Information Security Vocabulary Test to Assess Information Security Awareness - An Exploratory Study
    Kruger, H. A.
    Drevin, L.
    Steyn, T.
    [J]. PROCEEDINGS OF THE SOUTH AFRICAN INFORMATION SECURITY MULTI-CONFERENCE, 2010, : 13 - 22
  • [46] Information Systems and Case Management Practice Series: Introduction to Information Systems and Case Management Information System, Part I (of III)
    Mastrian, Kathleen
    McGonigle, Dee
    Pavlekovsky, Kim
    [J]. PROFESSIONAL CASE MANAGEMENT, 2007, 12 (03) : 181 - 183
  • [47] BUSINESS PROCESSES MANAGEMENT AS SUPPORT TOOL IN THE INFORMATION SECURITY MANAGEMENT
    Della Flora, Fernando
    Tolfo, Cristiano
    [J]. REVISTA GEINTEC-GESTAO INOVACAO E TECNOLOGIAS, 2016, 6 (01): : 2756 - 2770
  • [48] An Information Security Management System Based on "Five-in-one"
    Li Wencui
    Shu Xinjian
    LiXiong
    Gao Hui
    Liu Bo
    Wang Chunying
    Yang Ying
    [J]. PROCEEDINGS OF THE 2016 4TH INTERNATIONAL CONFERENCE ON ELECTRICAL & ELECTRONICS ENGINEERING AND COMPUTER SCIENCE (ICEEECS 2016), 2016, 50 : 743 - 745
  • [49] Security Policy on Logistics Management Information System Based on Web
    Huang, Linna
    Liu, Fenghua
    [J]. PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION APPLICATIONS (ICCIA 2012), 2012, : 1211 - 1214
  • [50] Study on the general defects in the information security management system (ISMS)
    Kwon, Sungho
    Jang, Sangsoo
    Lee, Jaeill
    [J]. INFORMATION PROCESSING IN THE SERVICE OF MANKIND AND HEALTH, 2006, : 463 - +