A Collaborative Process Based Risk Analysis for Information Security Management Systems

被引:0
|
作者
Karabacak, Bilge [1 ]
Ozkan, Sevgi [2 ]
机构
[1] TUBITAK, Ankara, Turkey
[2] METU, Ankara, Turkey
关键词
ISO/IEC 27001:2005; information security; risk analysis; flow chart; process approach;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Today, many organizations quote intent for ISO/IEC 27001:2005 certification. Also, some organizations are en route to certification or already certified. Certification process requires performing a risk analysis in the specified scope. Risk analysis is a challenging process especially when the topic is information security. Today, a number of methods and tools are available for information security risk analysis. The hard task is to use the best fit for the certification. In this work we have proposed a process based risk analysis method which is suitable for ISO/IEC 27001:2005 certifications. Our risk analysis method allows the participation of staff to the determination of the scope and provides a good fit for the certification process. The proposed method has been conducted for an organization and the results of the applications are shared with the audience. The proposed collaborative risk analysis method allows for the participation of staff and managers while still being manageable in a timely manner to uncover crucial information security risks.
引用
收藏
页码:182 / 192
页数:11
相关论文
共 50 条
  • [2] Enterprise Risk Management and Information Systems Security Risk
    Olson, David L.
    Wu, Desheng
    [J]. PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON RISK MANAGEMENT & GLOBAL E-BUSINESS, VOLS I AND II, 2009, : 1 - 5
  • [3] An Ontology-Based Security Risk Management Model for Information Systems
    Arogundade, Oluwasefunmi T.
    Abayomi-Alli, Adebayo
    Misra, Sanjay
    [J]. ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2020, 45 (08) : 6183 - 6198
  • [4] System dynamics based approach to risk management for security in information systems
    Trcek, Denis
    [J]. PROCEEDINGS OF THE 11TH WSEAS INTERNATIONAL CONFERENCE ON SYSTEMS, VOL 2: SYSTEMS THEORY AND APPLICATIONS, 2007, : 347 - +
  • [5] An Ontology-Based Security Risk Management Model for Information Systems
    Oluwasefunmi T. Arogundade
    Adebayo Abayomi-Alli
    Sanjay Misra
    [J]. Arabian Journal for Science and Engineering, 2020, 45 : 6183 - 6198
  • [6] A meta-process for information security risk management
    Papadaki, Katerina
    Polemi, Nineta
    Damilos, Dimitrios Konnos
    [J]. GLOBAL E-SECURITY, PROCEEDINGS, 2008, 12 : 257 - +
  • [7] A meta-process for information security risk management
    Papadaki, Katerina
    Polemi, Despina
    [J]. INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2008, 1 (04) : 336 - 343
  • [8] Resilience Analysis of Collaborative Process Management Systems
    de Vrieze, Paul
    Xu, Lai
    [J]. COLLABORATION IN A HYPERCONNECTED WORLD, 2016, 480 : 124 - 133
  • [9] A Dependency analysis for Information Security and Risk Management
    Krishna, B. Chaitanya
    Subrahmanyam, Kodukula
    Kim, Tai-hoon
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2015, 9 (08): : 205 - 210
  • [10] S-Port: Collaborative Security Management of Port Information Systems
    Polemi, Despoina
    Ntouskas, Theodoros
    Georgakakis, Emmanouil
    Douligeris, Christos
    Theoharidou, Marianthi
    Gritzalis, Dimitris
    [J]. 2013 FOURTH INTERNATIONAL CONFERENCE ON INFORMATION, INTELLIGENCE, SYSTEMS AND APPLICATIONS (IISA 2013), 2013, : 225 - 230