Idea: A Reference Platform for Systematic Information Security Management Tool Support

被引:0
|
作者
Mueller, Ingo [1 ]
Han, Jun [1 ]
Schneider, Jean-Guy [1 ]
Versteeg, Steven [2 ]
机构
[1] Swinburne Univ Technol, Hawthorn, Vic 3122, Australia
[2] CA Technol Pacific, CA Labs, Melbourne, Vic 3004, Australia
来源
ENGINEERING SECURE SOFTWARE AND SYSTEMS | 2011年 / 6542卷
基金
澳大利亚研究理事会;
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The ISO 27001 standard specifies an information security management system (ISMS) as a means to implement security best practices for IT systems. Organisations that implement an ISMS typically experience various challenges such as enforcing a common vocabulary, limiting human errors and integrating existing management tools and security mechanisms. However, ISO 27001 does not provide guidance on these issues because tool support is beyond its scope, leaving organisations to start "from scratch" with manual and usually paper document-driven approaches. We propose a novel reference platform for security management that provides the foundation for systematic and automated ISMS tool support. Our platform consists of a unified information model, an enterprise-level repository and an extensible application and integration platform that aid practitioners in tackling the aforementioned challenges. This paper motivates and outlines the key elements of our approach and presents a first proof-of-concept prototype implementation.
引用
收藏
页码:256 / +
页数:2
相关论文
共 50 条
  • [41] A framework and tool for the assessment of information security risk, the reduction of information security cost and the sustainability of information security culture
    Govender S.G.
    Kritzinger E.
    Loock M.
    Personal and Ubiquitous Computing, 2021, 25 (05) : 927 - 940
  • [42] An Information Cardiac Platform to Support Healthcare
    Georgieva-Tsaneva, Galya
    Gospodinova, Evgeniya
    Bogdanova, Galina
    Dimitrova, Diana
    INTERNATIONAL JOURNAL OF ONLINE AND BIOMEDICAL ENGINEERING, 2023, 19 (03) : 144 - 153
  • [43] Information security management frameworks and strategies in higher education institutions: a systematic review
    Merchan-Lima, Jorge
    Astudillo-Salinas, Fabian
    Tello-Oquendo, Luis
    Sanchez, Franklin
    Lopez-Fonseca, Gabriel
    Quiroz, Dorys
    ANNALS OF TELECOMMUNICATIONS, 2021, 76 (3-4) : 255 - 270
  • [44] Information security management frameworks and strategies in higher education institutions: a systematic review
    Jorge Merchan-Lima
    Fabian Astudillo-Salinas
    Luis Tello-Oquendo
    Franklin Sanchez
    Gabriel Lopez-Fonseca
    Dorys Quiroz
    Annals of Telecommunications, 2021, 76 : 255 - 270
  • [45] Information Technology and Communication as Reference Practices in Knowledge Management: A Systematic Review of the Literature
    Lache, L.
    Leon, A. P.
    Bravo, E.
    Becerra, L. E.
    Forero, D.
    UIS INGENIERIAS, 2016, 15 (01): : 27 - 40
  • [46] Laboratory support for information security education
    Miloslavskaya, N
    Tolstoy, A
    Ushakov, D
    INFORMATION SECURITY MANAGEMENT, EDUCATION AND PRIVACY, 2004, 148 : 101 - 115
  • [47] The 3LGM2-tool to support information management in health care
    Winter, Alfred
    INFORMATION PROCESSING IN THE SERVICE OF MANKIND AND HEALTH, 2006, : 539 - 541
  • [48] PLM Reference Model for Integrated Idea and Innovation Management
    Loewer, Manuel
    Heller, Jan Erik
    PRODUCT LIFECYCLE MANAGEMENT FOR A GLOBAL MARKET (PLM 2014), 2014, 442 : 257 - 266
  • [49] Application of the Information Security Services Platform Cloud
    Ping, Deng
    PROCEEDINGS OF THE 2016 INTERNATIONAL CONFERENCE ON INTELLIGENT CONTROL AND COMPUTER APPLICATION, 2016, 30 : 331 - 334
  • [50] PLM reference model for integrated idea and innovation management
    Löwer, Manuel
    Heller, Jan Erik
    IFIP Advances in Information and Communication Technology, 2014, 442 : 257 - 266