ISO Security Standards as a Leverage on IT Security Management
Igli Tashi, Solange Ghernaouti-Hallie
Abstract
Open-access reader
Igli Tashi, Solange Ghernaouti-Hallie
Abstract
Open-access reader
Information security is a very important component in the context of an organization's dependence on ICT.The operational environment where these technologies are operating is a very complex one.Offering a good level of protection by information security process needs a well defined managerial framework.This paper discusses the reasons why having a well defined managerial security framework is needed in an information security area, as well as which are the tools to build and implement such a management framework.After a short presentation, two international standards related to Information Security Management, the ISO 17799:2005 and ISO 27001 standards, and the implications of being conforming to these standards are analysed and their advantages and limits in a security management framework are pointed out.
OpenAlex reports 4 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Information security is a very important component in the context of an organization's dependence on ICT.The operational environment where these technologies are operating is a very complex one.Offering a good level of protection by information security process needs a well defined managerial framework.This paper discusses the reasons why having a well defined managerial security framework is needed in an information security area, as well as which are the tools to build and implement such a management framework.After a short presentation, two international standards related to Information Security Management, the ISO 17799:2005 and ISO 27001 standards, and the implications of being conforming to these standards are analysed and their advantages and limits in a security management framework are pointed out.
Key concepts: ITIL security management, Information security management system, Information security management, Security information and event management, Standard of Good Practice, Information security, Certified Information Security Manager, Information security standards