Security Framework for Information Systems

被引:0
|
作者
Martins, Jose [1 ]
dos Santos, Henrique [2 ]
Nunes, Paulo [1 ]
机构
[1] Acad Mil Cinamil, Lisbon, Portugal
[2] Univ Minho, Dept Informat Syst, P-4719 Guimaraes, Portugal
关键词
Information systems; information warfare; information security management and analysis and evaluation of risk;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Nowadays, information is one of the most important resources in an organization, supporting most of the business processes. So, organizations must try to guarantee at all times information's fundamental properties: confidentiality, integrity, and availability. Information Systems are a determining factor for the organization's capability, consisting of a tool that stimulates its productivity, indispensable in the decision making process at the various levels of management. The current network society supported primarily through Internet, presents new threats to information networks that support organizational Information Systems, independently of their dimension, nature, organization and technological resources. This scenario requires the utilization of a Security Framework in order to guarantee the information security, and also to integrate a set of different organizational views: a scientific community (conceptual model); decider's perception (behavioural model); and a technological model, as support for business processes. An established security policy and operational identification and evaluation methodology of risk must be distinguished in order to protect an organization from threats towards its information systems or information resources which it is responsible for. In this paper we propose a Security Framework for organizational Information Systems, to guarantee the security of the major information actives and to serve as a possible model of security information management, to supporting the decision making process on information security and management. We search to minimize the possible actions of Information Warfare / Competitive Intelligence, outlining in this framework the various standards of good information security practises. We have as an objective to guarantee the protection of Information Systems from the various methods of attack in use and types of weapons utilized.
引用
收藏
页码:164 / 176
页数:13
相关论文
共 50 条
  • [1] INFORMATION SYSTEMS SECURITY AND SECURITY EXTENSION IN JERSEY RESTFUL FRAMEWORK
    Kosmajac, Dijana
    Vujovic, Vladimir
    [J]. 2012 20TH TELECOMMUNICATIONS FORUM (TELFOR), 2012, : 1556 - 1559
  • [2] An Information Theoretic Framework for Biometric Security Systems
    Lai, Lifeng
    Ho, Siu-Wai
    Poor, H. Vincent
    [J]. ADVANCES IN BIOMETRICS, 2009, 5558 : 879 - +
  • [3] An integral framework for information systems security management
    Trcek, D
    [J]. COMPUTERS & SECURITY, 2003, 22 (04) : 337 - 360
  • [4] Enterprise Information Systems Security: A Conceptual Framework
    Chaudhry, Peggy E.
    Chaudhry, Sohail S.
    Reese, Ronald
    Jones, Darryl S.
    [J]. RE-CONCEPTUALIZING ENTERPRISE INFORMATION SYSTEMS, 2012, 105 : 118 - +
  • [5] Information systems security and the information systems development project Towards a framework for their integration
    Tryfonas, T
    Kiountouzis, E
    [J]. SECURITY IN THE INFORMATION SOCIETY: VISIONS AND PERSPECTIVES, 2002, 86 : 347 - 356
  • [6] Modernization Framework to Enhance the Security of Legacy Information Systems
    Khan, Musawwer
    Ali, Islam
    Nisar, Wasif
    Saleem, Muhammad Qaiser
    Ahmed, Ali S.
    Elamin, Haysam E.
    Mehmood, Waqar
    Shafiq, Muhammad
    [J]. INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2022, 32 (01): : 543 - 555
  • [7] An Information Security Assessments Framework for Power Control Systems
    Wang, Yufei
    Zhang, Tao
    Ma, Yuanyuan
    Zhang, Bo
    [J]. ENERGY AND POWER TECHNOLOGY, PTS 1 AND 2, 2013, 805-806 : 980 - 984
  • [8] INFORMATION SECURITY IN THE SMALL SYSTEMS CONTEXT - A FRAMEWORK FOR UNDERSTANDING
    GABLE, GG
    HIGHLAND, HJ
    [J]. COMPUTER SECURITY, 1993, 37 : 37 - 51
  • [9] Information Systems Strategy and Security Policy: A Conceptual Framework
    Kamariotou, Maria
    Kitsios, Fotis
    [J]. ELECTRONICS, 2023, 12 (02)
  • [10] A framework for evaluating the information security of e-learning systems
    Eibl, Christian J.
    von Solms, Basic S. H.
    Schubert, Sigrid
    [J]. INFORMATION TECHNOLOGIES AT SCHOOL, 2006, : 83 - 94