A Model to Assess the Maturity Level of the Risk Management Process in Information Security

被引:6
|
作者
Mayer, Janice [1 ]
Fagundes, Leonardo Lemes [1 ]
机构
[1] Univ Vale Rio dos Sinos, Sao Leopoldo, RS, Brazil
关键词
Risk Management; Maturity Model; Information Security;
D O I
10.1109/INMW.2009.5195935
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The Risk Management (RM) process comprises coordinated activities' aimed at guiding and controlling an organization as far as risks are concerned. These activities encompass the definition of the context of analysis, assessment, treatment, acceptance, as well as the communication and the monitoring of information security risks. Organizations should implement RM in a consistent, systematic manner in order to achieve compliance with current laws, standards and regulations, and also meet mandatory requirements for the certification of an Information Security Management System. However, in the context of information security, no reference was found in literature for a model to assess the maturity level of an RM process. In order to overcome this problem, this study describes the structure of a model for the assessment of the maturity level of the RM process in the realm of Information Security. The designed model basically consists of a set of best practices, totally aligned with standard ISO/IEC 27005 and comprised of: (I) three stages; (2) five maturity levels; (3) forty-three control objectives; (4) one control map; (5) one assessment instrument relative to the maturity level of the activities of the RM process; (6) an accountability matrix relative to each activity of the process and also a (7) risk scorecard.
引用
收藏
页码:61 / 70
页数:10
相关论文
共 50 条
  • [1] Tool to Assess the Maturity Level of the Risk Management of a Software Development Process
    Gaffo, Fernando Henrique
    Brigano, Gabriel Ulian
    Aoki Horita, Flavio Eduardo
    de Barros, Rodolfo Miranda
    [J]. PROCEEDINGS OF THE 2013 8TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI 2013), 2013,
  • [2] Organisational Information Security Management Maturity Model
    Zammani, Mazlina
    Razali, Rozilawati
    Singh, Dalbir
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (09) : 668 - 678
  • [3] Process security management: Assess the threats, control the risk
    Marszal, EM
    [J]. CHEMICAL ENGINEERING, 2003, 110 (01) : 42 - 46
  • [4] A Security Management Assurance Model to holistically assess the Information Security posture
    Tashi, Igli
    Ghernaouti-Helie, Solange
    [J]. 2009 INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY (ARES), VOLS 1 AND 2, 2009, : 756 - 761
  • [5] Risk Evaluation Process Model of Information Security
    Liu Jing
    [J]. 2009 INTERNATIONAL CONFERENCE ON MEASURING TECHNOLOGY AND MECHATRONICS AUTOMATION, VOL II, 2009, : 321 - 324
  • [6] Information security risk assessment model for risk management
    Wawrzyniak, Dariusz
    [J]. TRUST, PRIVACY, AND SECURITY IN DIGITAL BUSINESS, PROCEEDINGS, 2006, 4083 : 21 - 30
  • [7] An approach to simultaneously assess operational risk and maturity levels in information technology management
    Moinzad, Hossein
    Tarokh, Mohammad Jafar
    Taghavifard, Mohammad Taghi
    [J]. JOURNAL OF OPERATIONAL RISK, 2021, 16 (02): : 19 - 47
  • [8] A meta-process for information security risk management
    Papadaki, Katerina
    Polemi, Nineta
    Damilos, Dimitrios Konnos
    [J]. GLOBAL E-SECURITY, PROCEEDINGS, 2008, 12 : 257 - +
  • [9] A meta-process for information security risk management
    Papadaki, Katerina
    Polemi, Despina
    [J]. INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2008, 1 (04) : 336 - 343
  • [10] Maturity assessment and process improvement for information security management in small and medium enterprises
    Cholez, Herve
    Girard, Frederic
    [J]. JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2014, 26 (05) : 496 - 503