Information Security Management: A Case Study in a Portuguese Military Organization

被引:1
|
作者
Martins, Jose [1 ]
dos Santos, Henrique [2 ]
Rosinha, Antonio [1 ]
Valente, Agostinho [3 ]
机构
[1] Acad Mil, Ctr Invest Acad Mil CINAMIL, Lisbon, Portugal
[2] Univ Minho, DSI, Guimaraes, Portugal
[3] Inst Geog Exercito, Lisbon, Portugal
关键词
Decision-Making Process; Information Security; Information Security Case Study; Information Security Dimensions; Information Security Incidents;
D O I
10.4018/ijcwt.2013070103
中图分类号
D0 [政治学、政治理论];
学科分类号
0302 ; 030201 ;
摘要
The authors present a Case Study conducted in a Portuguese military organization, to answer the following research questions: (1) what are the most relevant dimensions and categories of information security controls applied in military organizations? (2) What are the main scenarios of information security incidents that are expected to occur? (3) What is the decision process used for planning and selection information security controls? This study reveals that: (1) information security within the military organization is built on the basis of physical and human attack vectors, and targeting the infrastructure that supports the flow of information in the organization; (2) the information security controls applied in the military organization are included in ISO/IEC 27001; (3) planning and selection of applied information security controls are made by decision makers and information security specialists. It appears that specialists impose their planning options essentially seeking to select and retrieve past successful information security cases.
引用
收藏
页码:32 / 48
页数:17
相关论文
共 50 条
  • [1] Information Architectures Definition - A Case Study in a Portuguese Local Public Administration Organization
    Sa, Filipe
    Rocha, Alvaro
    [J]. ADVANCES IN INFORMATION SYSTEMS AND TECHNOLOGIES, 2013, 206 : 399 - 410
  • [2] A Case Study on Risk Management of Enterprise Information Security
    Huang, Rengen
    Zhu, Zhen
    [J]. 2015 2nd International Conference on Creative Education (ICCE 2015), Pt 2, 2015, 11 : 201 - 208
  • [3] Strengthen Military Academy's Information Security Management
    Liu Qingguo
    Zhang Wei
    [J]. MINES 2009: FIRST INTERNATIONAL CONFERENCE ON MULTIMEDIA INFORMATION NETWORKING AND SECURITY, VOL 1, PROCEEDINGS, 2009, : 182 - +
  • [4] A Study of Effect of Information Security Management System[ISMS] Certification on Organization Performance
    Park, Cheol-Soon
    Jang, Sang-Soo
    Park, Yong-Tae
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2010, 10 (03): : 10 - 21
  • [5] Information Security Risk Management and Incompatible Parts of Organization
    Talabeigi, Elham
    Naeeini, Seyyed Gholamreza Jalali
    [J]. JOURNAL OF INDUSTRIAL ENGINEERING AND MANAGEMENT-JIEM, 2016, 9 (04): : 964 - 977
  • [6] A New Approach to Information Security Assessment: a case study in a Brazilian healthcare organization
    Ribas, Carlos Eduardo
    Ferreira Francisco, Antonio Joao
    Yamamoto, Jorge Futoshi
    Burattini, Marcelo Nascimento
    [J]. WMSCI 2011: 15TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL II, 2011, : 219 - 223
  • [7] INFORMATION RESOURCES MANAGEMENT BASED ON FEEDBACK THEORY IN A MILITARY ORGANIZATION
    Gherman, Laurian
    Mosoiu, Ovidiu
    Bucinschi, Vasile
    [J]. ELEARNING VISION 2020!, VOL I, 2016, : 115 - 121
  • [8] MANAGEMENT OF INFORMATION SECURITY RISKS IN A FEDERAL PUBLIC INSTITUTION: A CASE STUDY
    Soares Souza, Jackson Gomes
    Arima, Carlos Hideo
    Nogueira de Oliveira, Renata Maria
    Akabane, Getulio Kazue
    Galegale, Napoleao Verardi
    [J]. REVISTA ENIAC PESQUISA, 2016, 5 (02): : 240 - 256
  • [9] Collaborative Learning : A Case Study on Information Security and Auditing Management Course
    Parkavi, R.
    Karthikeyan, P.
    Abdullah, A. Sheik
    [J]. 2022 International Conference for Advancement in Technology, ICONAT 2022, 2022,
  • [10] Challenges of information security incident learning: An industrial case study in a Chinese healthcare organization
    He, Ying
    Johnson, Chris
    [J]. INFORMATICS FOR HEALTH & SOCIAL CARE, 2017, 42 (04): : 393 - 408