A framework for the management of information security risks

被引:12
|
作者
Jones, A. [1 ]
机构
[1] BTs Secur Res Ctr Adastral Pk, Adastral Pk, England
关键词
Security of data;
D O I
10.1007/s10550-007-0005-9
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
This paper looks at the development of a framework for information security risk assessments within an organisation. A risk framework is a convenient and communicable tool that can be used to describe the principles and essential components of the security risk management process of an organisation. The framework shows how significant risks can be identified, assessed and treated. It also explains the measures that can be taken to mitigate or 'treat' the risk exposure of the organisation for the future. The risk framework will provide a common language, which can be used by all of the parties that are involved in the process, from the members of the board, through the security and audit staffs, to the end users of the systems, as a vehicle for communication and improved understanding. In addition, a risk framework will provide a high level outline for the way in which an organisation will implement information security risk management and define the roles of the key participants in the process.
引用
收藏
页码:30 / 36
页数:7
相关论文
共 50 条
  • [31] An Intelligent Agent-Based Framework for Information Security Management
    Jiang, Chengzhi
    Zhang, Bo
    Yu, Yong
    Zhang, Xiaojian
    INSTRUMENTATION, MEASUREMENT, CIRCUITS AND SYSTEMS, 2012, 127 : 807 - 814
  • [32] Framework to implement information security management systems: An asset to project management processes
    Mena, Alvaro
    2018 37TH INTERNATIONAL CONFERENCE OF THE CHILEAN COMPUTER SCIENCE SOCIETY (SCCC), 2018,
  • [33] Research on Building of Information System Risks Management Framework of Commercial Banks
    Yang Feng
    Shao Pei-ji
    Li Dong
    Liang Li-qin
    PROCEEDINGS OF 2009 INTERNATIONAL CONFERENCE ON PUBLIC ADMINISTRATION (5TH), VOL III, 2009, : 871 - 877
  • [34] Governance and Management of Organizations with Cloud Supported Services Recommendations for Risks of Information Security
    Silva, Elcelina
    Soares, Bruno Horta
    2018 13TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI), 2018,
  • [35] Analytical Hierarchy Process Approach for the Metrics of Information Security Management Framework
    Moeti, Michael
    Kalema, Billy Mathias
    2014 SIXTH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE, COMMUNICATION SYSTEMS AND NETWORKS (CICSYN), 2014, : 89 - 94
  • [36] INFORMATION SECURITY MANAGEMENT FRAMEWORK SUITABILITY ESTIMATION FOR SMALL AND MEDIUM ENTERPRISE
    Kauspadiene, Laima
    Ramanauskaite, Simona
    Cenys, Antanas
    TECHNOLOGICAL AND ECONOMIC DEVELOPMENT OF ECONOMY, 2019, 25 (05) : 979 - 997
  • [37] Balancing performance measures for information security management - A balanced scorecard framework
    Huang, Shi-Ming
    Lee, Chia-Ling
    Kao, Ai-Chin
    INDUSTRIAL MANAGEMENT & DATA SYSTEMS, 2006, 106 (1-2) : 242 - 255
  • [38] Corroborative Intersection of the Information Security Standards and the Legal Framework on Data Management
    Zulhuda, Sonny
    SECOND INTERNATIONAL CONFERENCE ON COMPUTER AND ELECTRICAL ENGINEERING, VOL 1, PROCEEDINGS, 2009, : 200 - 203
  • [39] A security management information model derivation framework:: From goals to configurations
    Laborde, R
    Barrère, F
    Benzekri, A
    FORMAL ASPECTS IN SECURITY AND TRUST, 2006, 3866 : 217 - 234
  • [40] Alcatel information security framework
    Hayes, J
    ALCATEL TELECOMMUNICATIONS REVIEW, 2002, (04): : 273 - 279