1998Information Management & Computer SecurityRequires access

Information security management (3): the Code of Practice for Information Security Management (BS 7799)

Rossouw von Solms

Open publisher page 56 citations

Abstract

Information security has become very important in most organizations. An acceptable level of information security can only be introduced and maintained if the correct set of security controls, both procedural and technical, is identified, implemented and maintained. The process of identifying the most effective set of security controls can be a very complicated, resource‐intensive process. A number of large British companies have joined forces to establish a Code of Practice for Information Security Management. This document provides guidelines to any organization to identify and introduce a set of controls that will provide an acceptable level of protection to the information resources. This paper briefly discusses the BS 7799 British standard.

About this research paper

What this paper is about

Information security has become very important in most organizations. An acceptable level of information security can only be introduced and maintained if the correct set of security controls, both procedural and technical, is identified, implemented and maintained. The process of identifying the most effective set of security controls can be a very complicated, resource‐intensive process. A number of large British companies have joined forces to establish a Code of Practice for Information Security Management. This document provides guidelines to any organization to identify and introduce a set of controls that will provide an acceptable level of protection to the information resources. This paper briefly discusses the BS 7799 British standard.

Why it matters

OpenAlex reports 56 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Information security has become very important in most organizations. An acceptable level of information security can only be introduced and maintained if the correct set of security controls, both procedural and technical, is identified, implemented and maintained. The process of identifying the most effective set of security controls can be a very complicated, resource‐intensive process. A number of large British companies have joined forces to establish a Code of Practice for Information Security Management. This document provides guidelines to any organization to identify and introduce a set of controls that will provide an acceptable level of protection to the information resources. This paper briefly discusses the BS 7799 British standard.

Key concepts: Standard of Good Practice, Information security management, Information security, Computer science, Security controls, Security information and event management, Certified Information Security Manager, Set (abstract data type)

Related papers

Back to paper searchBrowse research topicsOriginal source
Information security management (3): the Code of Practice for Information Security Management (BS 7799) — Research Paper | ScholarLens