Framework to implement information security management systems: An asset to project management processes

被引:0
作者
Mena, Alvaro [1 ]
机构
[1] Univ Costa Rica, Informat Empresarial, San Jose, Costa Rica
来源
2018 37TH INTERNATIONAL CONFERENCE OF THE CHILEAN COMPUTER SCIENCE SOCIETY (SCCC) | 2018年
关键词
data protection; framework; information security; information security management system; methodology; project management;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
This article shows how the creation of a quality framework, composed by processes to implement an information security management system (ISMS), provides a methodological approach and assets that can be used in project management processes. The content of this framework meets the requirements suggested by the standard ISO/IEC 27001 for implementing an ISMS and they were systematized by means of the SPEM 2.0 meta-model and the Eclipse Process Framework Composer software. The results show how it is possible to derive benefits for the project management processes recommended by the Management Institute Project Management (PMI) and also offers benefits in terms of quality. Besides it provides a systematic approach that can be replicated to comprise knowledge in project management methodology.
引用
收藏
页数:8
相关论文
共 11 条
[1]  
[Anonymous], 2009, ECL PROC FRAM EPF CO
[2]  
[Anonymous], 2017, A Guide to the SCRUM BODY OF KNOWLEDGE (SBOK TM GUIDE) Third Edition A Comprehensive Guide to Deliver Projects using Scrum Includes two chapters about Scaling Scrum for Large Projects and the Enterprise
[3]  
[Anonymous], 2018, 270002018E ISOIEC
[4]  
[Anonymous], 2003, 10006 INTEISO INTECO
[5]  
Caralli Richard, 2007, Technical Report CMU/SEI-2007-TR-012
[6]  
[ISO IEC], 2005, 27001 ISOIEC
[7]  
*OMG, 2008, SOFTW SYST PROC ENG
[8]  
Tipton H.F., 2008, Information security management handbook
[9]  
Vacca J. R., 2010, MANAGING INFORM SECU
[10]  
Vasudevan V., 2015, ISO270012013