A framework for the management of information security risks

被引:12
|
作者
Jones, A. [1 ]
机构
[1] BTs Secur Res Ctr Adastral Pk, Adastral Pk, England
关键词
Security of data;
D O I
10.1007/s10550-007-0005-9
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
This paper looks at the development of a framework for information security risk assessments within an organisation. A risk framework is a convenient and communicable tool that can be used to describe the principles and essential components of the security risk management process of an organisation. The framework shows how significant risks can be identified, assessed and treated. It also explains the measures that can be taken to mitigate or 'treat' the risk exposure of the organisation for the future. The risk framework will provide a common language, which can be used by all of the parties that are involved in the process, from the members of the board, through the security and audit staffs, to the end users of the systems, as a vehicle for communication and improved understanding. In addition, a risk framework will provide a high level outline for the way in which an organisation will implement information security risk management and define the roles of the key participants in the process.
引用
收藏
页码:30 / 36
页数:7
相关论文
共 50 条
  • [41] Security Framework for Information Systems
    Martins, Jose
    dos Santos, Henrique
    Nunes, Paulo
    [J]. PROCEEDINGS OF THE 8TH EUROPEAN CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2009, : 164 - 176
  • [42] Information security governance framework
    Faculty of Informatics, Kogakuin University, Japan
    不详
    不详
    不详
    不详
    不详
    [J]. Proc ACM Conf Computer Commun Secur, (1-5):
  • [43] An information security governance framework
    Da Veiga, A.
    Eloff, J. H. P.
    [J]. INFORMATION SYSTEMS MANAGEMENT, 2007, 24 (04) : 361 - 372
  • [44] A FRAMEWORK FOR INFORMATION SECURITY EVALUATION
    VONSOLMS, R
    VANDEHAAR, H
    VONSOLMS, SH
    CAELLI, WJ
    [J]. INFORMATION & MANAGEMENT, 1994, 26 (03) : 143 - 153
  • [45] A framework for the governance of information security
    Posthumus, S
    von Solms, R
    [J]. COMPUTERS & SECURITY, 2004, 23 (08) : 638 - 646
  • [46] A responsibility framework for information security
    Posthumus, S
    von Solms, R
    [J]. SECURITY MANAGEMENT, INTEGRITY, AND INTERNAL CONTROL IN INFORMATION SYSTEMS, 2005, 193 : 205 - 221
  • [47] Management of cyber risks in the library: analysis of information security awareness of Estonian library employees
    Kont, Kate-Riin
    [J]. LIBRARY MANAGEMENT, 2024, 45 (1/2) : 118 - 140
  • [48] Corporate IT Risk Management Model: a Holistic view at Managing Information System Security Risks
    Spremic, Mario
    [J]. PROCEEDINGS OF THE ITI 2012 34TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY INTERFACES (ITI), 2012, : 299 - 304
  • [49] Security Risks and their Management in Cloud Computing
    Khan, Afnan Ullah
    Oriol, Manuel
    Kiran, Mariam
    Jiang, Ming
    Djemame, Karim
    [J]. 2012 IEEE 4TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), 2012,
  • [50] A checklist based evaluation framework to measure risk of information security management systems
    Mortazavi S.A.R.
    Safi-Esfahani F.
    [J]. International Journal of Information Technology, 2019, 11 (3) : 517 - 534