Idea: A Reference Platform for Systematic Information Security Management Tool Support

被引:0
|
作者
Mueller, Ingo [1 ]
Han, Jun [1 ]
Schneider, Jean-Guy [1 ]
Versteeg, Steven [2 ]
机构
[1] Swinburne Univ Technol, Hawthorn, Vic 3122, Australia
[2] CA Technol Pacific, CA Labs, Melbourne, Vic 3004, Australia
来源
ENGINEERING SECURE SOFTWARE AND SYSTEMS | 2011年 / 6542卷
基金
澳大利亚研究理事会;
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The ISO 27001 standard specifies an information security management system (ISMS) as a means to implement security best practices for IT systems. Organisations that implement an ISMS typically experience various challenges such as enforcing a common vocabulary, limiting human errors and integrating existing management tools and security mechanisms. However, ISO 27001 does not provide guidance on these issues because tool support is beyond its scope, leaving organisations to start "from scratch" with manual and usually paper document-driven approaches. We propose a novel reference platform for security management that provides the foundation for systematic and automated ISMS tool support. Our platform consists of a unified information model, an enterprise-level repository and an extensible application and integration platform that aid practitioners in tackling the aforementioned challenges. This paper motivates and outlines the key elements of our approach and presents a first proof-of-concept prototype implementation.
引用
收藏
页码:256 / +
页数:2
相关论文
共 50 条
  • [1] BUSINESS PROCESSES MANAGEMENT AS SUPPORT TOOL IN THE INFORMATION SECURITY MANAGEMENT
    Della Flora, Fernando
    Tolfo, Cristiano
    REVISTA GEINTEC-GESTAO INOVACAO E TECNOLOGIAS, 2016, 6 (01): : 2756 - 2770
  • [2] Information Visualization to Support Idea Management
    Candido, R.
    Lemos, R.
    Goncalves, A.
    IEEE LATIN AMERICA TRANSACTIONS, 2022, 20 (06) : 866 - 874
  • [3] APPLIED INFORMATION MANAGEMENT - MANAGEMENT REFERENCE MODEL - SECURITY METRICS
    Doucek, Petr
    IDIMT-2008: MANAGING THE UNMANAGEABLE, 2008, 25 : 81 - 106
  • [4] IT security management for industrial plants - An automated support tool
    Palmin, Anna
    Runde, Stefan
    Kobes, Pierre
    ATP EDITION, 2012, (03): : 34 - 40
  • [5] A Systematic Management Method of ISO Information Security Standards for Information Security Engineering Environments
    Suhaimi, Ahmad Iqbal Hakim
    Manji, Takashi
    Goto, Yuichi
    Cheng, Jingde
    INFORMATICS ENGINEERING AND INFORMATION SCIENCE, PT I, 2011, 251 : 370 - 384
  • [6] INFORMATION AND ANALYTICAL SUPPORT IN THE MANAGEMENT OF FINANCIAL SECURITY ENTERPRISE
    Orekhova, K. V.
    FINANCIAL AND CREDIT ACTIVITY-PROBLEMS OF THEORY AND PRACTICE, 2013, 2 (15): : 203 - 212
  • [7] An audit framework to support information system security management
    Pereira, Teresa
    Santos, Henrique M. Dinis
    INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2010, 3 (03) : 265 - 277
  • [8] Designing a Process Reference Model for Information Security Management Systems
    Mangin, Olivier
    Barafort, Beatrix
    Heymans, Patrick
    Dubois, Eric
    SOFTWARE PROCESS IMPROVEMENT AND CAPABILITY DETERMINATION, 2012, 290 : 129 - +
  • [9] SCMM-tool - Tool for computer automation of the information security management systems
    Sanchez, Luis Enrique
    Villafranca, Daniel
    Fernandez-Medina, Eduardo
    Piattini, Mario
    ICSOFT 2007: PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON SOFTWARE AND DATA TECHNOLOGIES, VOL SE: SOFTWARE ENGINEERING, 2007, : 311 - +
  • [10] Technical design of integrated management platform for information security and operation service
    Hou, Jiehua
    Shen, Yuhua
    Zou, Tun
    Ma, Tao
    Tobacco Science and Technology, 2014, (03): : 29 - 32