A framework for the management of information security risks

被引:12
|
作者
Jones, A. [1 ]
机构
[1] BTs Secur Res Ctr Adastral Pk, Adastral Pk, England
关键词
D O I
10.1007/s10550-007-0005-9
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
This paper looks at the development of a framework for information security risk assessments within an organisation. A risk framework is a convenient and communicable tool that can be used to describe the principles and essential components of the security risk management process of an organisation. The framework shows how significant risks can be identified, assessed and treated. It also explains the measures that can be taken to mitigate or 'treat' the risk exposure of the organisation for the future. The risk framework will provide a common language, which can be used by all of the parties that are involved in the process, from the members of the board, through the security and audit staffs, to the end users of the systems, as a vehicle for communication and improved understanding. In addition, a risk framework will provide a high level outline for the way in which an organisation will implement information security risk management and define the roles of the key participants in the process.
引用
收藏
页码:30 / 36
页数:7
相关论文
共 50 条
  • [1] Information security risks management framework - A step towards mitigating security risks in university network
    Joshi, Chanchala
    Singh, Umesh Kumar
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2017, 35 : 128 - 137
  • [2] A FRAMEWORK FOR INFORMATION SECURITY MANAGEMENT
    Angheluta, Dragos-Ionut
    Lupu, Luminita-Mihaela
    [J]. FROM MANAGEMENT OF CRISIS TO MANAGEMENT IN A TIME OF CRISIS, 2016, : 2 - 16
  • [3] A framework for the management of information security
    Leiwo, J
    Zheng, YL
    [J]. INFORMATION SECURITY, 1998, 1396 : 232 - 245
  • [4] Risks Management relating to Information Systems Security Treatment of IT Equipment Security Risks
    Baicu, Floarea
    Baicu, Andrei Mihai
    [J]. QUALITY-ACCESS TO SUCCESS, 2012, 13 (131): : 108 - 112
  • [5] Management of Information Security Risks in a Context of Uncertainty
    Azhmukhamedov, I. M.
    Vybornova, O. N.
    Brumshtein, Yu. M.
    [J]. AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2016, 50 (08) : 657 - 663
  • [6] A conceptual framework for information security management
    Finne, T
    [J]. COMPUTERS & SECURITY, 1998, 17 (04) : 303 - 307
  • [7] A Framework for Information Security Governance and Management
    Carcary, Marian
    Renaud, Karen
    McLaughlin, Stephen
    O'Brien, Conor
    [J]. IT PROFESSIONAL, 2016, 18 (02) : 22 - 30
  • [8] An Integrated Framework for Information Security Management
    Ma, Qingxiong
    Schmidt, Mark B.
    Pearson, J. Michael
    [J]. REVIEW OF BUSINESS, 2009, 30 (01): : 58 - 69
  • [9] A process framework for information security management
    Haufe, Knut
    Colomo-Palacios, Ricardo
    Dzombeta, Srdan
    Brandis, Knud
    Stantchev, Vladimir
    [J]. IJISPM-INTERNATIONAL JOURNAL OF INFORMATION SYSTEMS AND PROJECT MANAGEMENT, 2016, 4 (04): : 27 - 47
  • [10] An integral framework for information systems security management
    Trcek, D
    [J]. COMPUTERS & SECURITY, 2003, 22 (04) : 337 - 360