信息安全管理的流程框架

Knut Haufe, R. Colomo‐Palacios, Srdan Dzombeta, K. Brandis, V. Stantchev
{"title":"信息安全管理的流程框架","authors":"Knut Haufe, R. Colomo‐Palacios, Srdan Dzombeta, K. Brandis, V. Stantchev","doi":"10.12821/IJISPM040402","DOIUrl":null,"url":null,"abstract":"Securing sensitive organizational data has become increasingly vital to organizations. An Information Security Management System (ISMS) is a systematic approach for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an organization's information security. Key elements of the operation of an ISMS are ISMS processes. However, and in spite of its importance, an ISMS process framework with a description of ISMS processes and their interaction as well as the interaction with other management processes is not available in the literature. Cost benefit analysis of information security investments regarding single measures protecting information and ISMS processes are not in the focus of current research, mostly focused on economics. This article aims to fill this research gap by proposing such an ISMS process framework as the main contribution. It is based on a set of agreed upon ISMS processes in existing standards like ISO 27000 series, COBIT and ITIL. Within the framework, identified processes are described and their interaction and interfaces are specified. This framework helps to focus on the operation of the ISMS, instead of focusing on measures and controls. By this, as a main finding, the systemic character of the ISMS consisting of processes and the perception of relevant roles of the ISMS is strengthened.","PeriodicalId":43984,"journal":{"name":"IJISPM-International Journal of Information Systems and Project Management","volume":" ","pages":""},"PeriodicalIF":2.2000,"publicationDate":"2022-02-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"17","resultStr":"{\"title\":\"A process framework for information security management\",\"authors\":\"Knut Haufe, R. Colomo‐Palacios, Srdan Dzombeta, K. Brandis, V. Stantchev\",\"doi\":\"10.12821/IJISPM040402\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Securing sensitive organizational data has become increasingly vital to organizations. An Information Security Management System (ISMS) is a systematic approach for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an organization's information security. Key elements of the operation of an ISMS are ISMS processes. However, and in spite of its importance, an ISMS process framework with a description of ISMS processes and their interaction as well as the interaction with other management processes is not available in the literature. Cost benefit analysis of information security investments regarding single measures protecting information and ISMS processes are not in the focus of current research, mostly focused on economics. This article aims to fill this research gap by proposing such an ISMS process framework as the main contribution. It is based on a set of agreed upon ISMS processes in existing standards like ISO 27000 series, COBIT and ITIL. Within the framework, identified processes are described and their interaction and interfaces are specified. This framework helps to focus on the operation of the ISMS, instead of focusing on measures and controls. By this, as a main finding, the systemic character of the ISMS consisting of processes and the perception of relevant roles of the ISMS is strengthened.\",\"PeriodicalId\":43984,\"journal\":{\"name\":\"IJISPM-International Journal of Information Systems and Project Management\",\"volume\":\" \",\"pages\":\"\"},\"PeriodicalIF\":2.2000,\"publicationDate\":\"2022-02-02\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"17\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"IJISPM-International Journal of Information Systems and Project Management\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.12821/IJISPM040402\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q3\",\"JCRName\":\"MANAGEMENT\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"IJISPM-International Journal of Information Systems and Project Management","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.12821/IJISPM040402","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"MANAGEMENT","Score":null,"Total":0}
引用次数: 17

摘要

保护敏感的组织数据对组织来说越来越重要。信息安全管理系统(ISMS)是一种建立、实施、运行、监控、审查、维护和改进组织信息安全的系统方法。ISMS运作的关键要素是ISMS过程。然而,尽管它很重要,但文献中没有描述ISMS过程及其相互作用以及与其他管理过程相互作用的ISMS过程框架。关于保护信息和ISMS流程的单一措施的信息安全投资的成本效益分析不是当前研究的重点,主要集中在经济学上。本文旨在通过提出这样一个ISMS过程框架作为主要贡献来填补这一研究空白。它基于ISO 27000系列、COBIT和ITIL等现有标准中一组商定的ISMS流程。在该框架内,对已识别的过程进行了描述,并指定了它们的交互和接口。该框架有助于将重点放在ISMS的运作上,而不是放在措施和控制上。由此,作为一项主要发现,由过程和对ISMS相关角色的感知组成的ISMS的系统性特征得到了加强。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
A process framework for information security management
Securing sensitive organizational data has become increasingly vital to organizations. An Information Security Management System (ISMS) is a systematic approach for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an organization's information security. Key elements of the operation of an ISMS are ISMS processes. However, and in spite of its importance, an ISMS process framework with a description of ISMS processes and their interaction as well as the interaction with other management processes is not available in the literature. Cost benefit analysis of information security investments regarding single measures protecting information and ISMS processes are not in the focus of current research, mostly focused on economics. This article aims to fill this research gap by proposing such an ISMS process framework as the main contribution. It is based on a set of agreed upon ISMS processes in existing standards like ISO 27000 series, COBIT and ITIL. Within the framework, identified processes are described and their interaction and interfaces are specified. This framework helps to focus on the operation of the ISMS, instead of focusing on measures and controls. By this, as a main finding, the systemic character of the ISMS consisting of processes and the perception of relevant roles of the ISMS is strengthened.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
6.30
自引率
18.20%
发文量
99
审稿时长
12 weeks
期刊最新文献
Digitalization of revenue mobilization in an emerging economy: the new Institutional Theory perspective Software developers reasoning behind adoption and use of software development methods – a systematic literature review The characteristics of successful military IT projects: a cross-country empirical study An agile portfolio management model for the insurance sector: the APMI model Towards a framework for developing visual analytics in supply chain environments
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1