Information security management (3): the Code of Practice for Information Security Management (BS 7799)
Rossouw von Solms
Abstract
Rossouw von Solms
Abstract
Information security has become very important in most organizations. An acceptable level of information security can only be introduced and maintained if the correct set of security controls, both procedural and technical, is identified, implemented and maintained. The process of identifying the most effective set of security controls can be a very complicated, resource‐intensive process. A number of large British companies have joined forces to establish a Code of Practice for Information Security Management. This document provides guidelines to any organization to identify and introduce a set of controls that will provide an acceptable level of protection to the information resources. This paper briefly discusses the BS 7799 British standard.
OpenAlex reports 56 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Information security has become very important in most organizations. An acceptable level of information security can only be introduced and maintained if the correct set of security controls, both procedural and technical, is identified, implemented and maintained. The process of identifying the most effective set of security controls can be a very complicated, resource‐intensive process. A number of large British companies have joined forces to establish a Code of Practice for Information Security Management. This document provides guidelines to any organization to identify and introduce a set of controls that will provide an acceptable level of protection to the information resources. This paper briefly discusses the BS 7799 British standard.
Key concepts: Standard of Good Practice, Information security management, Information security, Computer science, Security controls, Security information and event management, Certified Information Security Manager, Set (abstract data type)