ISO/IEC 27001 Implementation in Public Organizations: A Case Study

被引:0
|
作者
Sussy, Bayona [1 ]
Wilber, Chauca [1 ]
Milagros, Lopez [1 ]
Carlos, Maldonado [1 ]
机构
[1] Univ Nacl Mayor San Marcos, Unidad Posgrado, Fac Ingn Sistemas & Informat, Av German Amezaga 375, Lima, Peru
关键词
critical success factors; NTP ISO/IEC 27001; information security management system; ISMS;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, due to the intensive use of information technology, the information security has become a crucial and strategic issue in organizational management. Various standards and guidelines for security information as ISO/IEC 27001, ISO/IEC 27002, and COBIT have been developed; however, organizations still face difficulties in their implementation. This paper presents the current situation of the ISO/IEC 27001 implementation process in Peruvian public organizations. As a result of literature review, the critical success factors for successful implementation of ISO/IEC 7001 were identified. Furthermore, it was conducted a review of the ISO/IEC 27001 implementation in five organizations, taking into consideration the critical success factors identified. From the results obtained, it is concluded that there is the need for considering not only technical, legal, and organizational issues but also factors related to people such as training, knowledge and awareness raising in order to get success of information security management.
引用
收藏
页数:6
相关论文
共 50 条
  • [31] Extension of ISO/IEC27001 to Mobile Devices Security Management
    Zhu, Xiaobo
    Zhu, Yunqian
    CYBER SECURITY, CNCERT 2018, 2019, 970 : 27 - 35
  • [32] Reviewing of ISO Systems implementation in National organizations (Case study:Isfahan organizations, Isfahan, Iran)
    Karimi, Maryam
    RECENT ADVANCES IN BUSINESS ADMINISTRATION, 2011, : 49 - 52
  • [33] The effect of ISO/IEC 27001 standard over open-source intelligence
    Qusef A.
    Alkilani H.
    PeerJ Computer Science, 2022, 8
  • [34] Information Security Management Systems - A Maturity Model Based on ISO/IEC 27001
    Proenca, Diogo
    Borbinha, Jose
    BUSINESS INFORMATION SYSTEMS (BIS 2018), 2018, 320 : 102 - 114
  • [35] NEW STANDARD ISO/IEC 27001:2013 OF INFORMATION SECURITY MANAGEMENT SYSTEM
    Drastich, Martin
    KNOWLEDGE FOR MARKET USE 2014: MEDIA AND COMMUNICATION IN THE 21ST CENTURY, 2014, : 387 - 393
  • [36] ISO/IEC 27001信息安全管理体系标准介绍
    本刊编辑部
    标准生活, 2010, (07) : 60 - 62
  • [37] ISO/IEC 27001:2013信息安全控制措施解析
    雷宏
    王贵杰
    质量与认证, 2015, (09) : 64 - 65+67
  • [38] The effect of ISO/IEC 27001 standard over open-source intelligence
    Qusef, Abdallah
    Alkilani, Hamzeh
    PEERJ COMPUTER SCIENCE, 2022, 8
  • [39] AUTOMATION OF AN INFORMATION SECURITY MANAGEMENT SYSTEM BASED ON THE ISO/IEC 27001 STANDARD
    de la Rosa Martin, Tonyse
    REVISTA UNIVERSIDAD Y SOCIEDAD, 2021, 13 (05): : 495 - 506
  • [40] Implementation of Azure DevOps to automate the processes of the ISO/IEC 29110 standard a Case Study
    Garcia, Josefina
    Jesus Minero, J.
    Lara, Elvia
    2022 11TH INTERNATIONAL CONFERENCE ON SOFTWARE PROCESS IMPROVEMENT, CIMPS, 2022, : 29 - 36