2007Journal of the Association for Information SystemsOpen access

ISO Security Standards as a Leverage on IT Security Management

Igli Tashi, Solange Ghernaouti-Hallie

Open full text 4 citations

Abstract

Information security is a very important component in the context of an organization's dependence on ICT.The operational environment where these technologies are operating is a very complex one.Offering a good level of protection by information security process needs a well defined managerial framework.This paper discusses the reasons why having a well defined managerial security framework is needed in an information security area, as well as which are the tools to build and implement such a management framework.After a short presentation, two international standards related to Information Security Management, the ISO 17799:2005 and ISO 27001 standards, and the implications of being conforming to these standards are analysed and their advantages and limits in a security management framework are pointed out.

Open-access reader

About this research paper

What this paper is about

Information security is a very important component in the context of an organization's dependence on ICT.The operational environment where these technologies are operating is a very complex one.Offering a good level of protection by information security process needs a well defined managerial framework.This paper discusses the reasons why having a well defined managerial security framework is needed in an information security area, as well as which are the tools to build and implement such a management framework.After a short presentation, two international standards related to Information Security Management, the ISO 17799:2005 and ISO 27001 standards, and the implications of being conforming to these standards are analysed and their advantages and limits in a security management framework are pointed out.

Why it matters

OpenAlex reports 4 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Information security is a very important component in the context of an organization's dependence on ICT.The operational environment where these technologies are operating is a very complex one.Offering a good level of protection by information security process needs a well defined managerial framework.This paper discusses the reasons why having a well defined managerial security framework is needed in an information security area, as well as which are the tools to build and implement such a management framework.After a short presentation, two international standards related to Information Security Management, the ISO 17799:2005 and ISO 27001 standards, and the implications of being conforming to these standards are analysed and their advantages and limits in a security management framework are pointed out.

Key concepts: ITIL security management, Information security management system, Information security management, Security information and event management, Standard of Good Practice, Information security, Certified Information Security Manager, Information security standards

Related papers

Back to paper searchBrowse research topicsOriginal source
ISO Security Standards as a Leverage on IT Security Management — Research Paper | ScholarLens