2014Unpublished venueRequires access

The measurement design of information security management system

Merry Nancylia, Eddy K Mudjtabar, Sarwono Sutikno, Yusep Rosmansyah

Open publisher page 16 citations

Abstract

Information is an asset, such as important business assets, has value to an organization and consequently must be well protected. In organizations, information becomes an important and must remain available, and its existence should be maintained from unauthorized access. The use of information by unauthorized parties could be used for negative purposes which would be detrimental to the organization. Therefore, information security must be implemented correctly in order to avoid the impact of loss to the organization. Information security must satisfy the elements of confidentiality, integrity and availability. The international standard ISO / IEC 27000: 2014, SNI ISO / IEC 27001: 2013 and SNI ISO / IEC 27002: 2013 are a standard for Information Security Management System that can be used for the organization. These standard are able to test the security of the information and to measure the effectiveness of an implemented Information Security Management System (ISMS) which has been adopted as SNI ISO / IEC 27004: 2013. The standardization of Information Security Management Systems need an adjustment, the version of ISO / IEC 27004. The latter has adopted the development of ISO / IEC 27000, ISO / IEC 27001 and ISO / IEC 27002 which is required the measurement design of Information Security Management System. This study results in the design of the size of the Information Security Management System in accordance with the rules of international standards and the latest ISO standards. So it can be a reference for various organizations. This study aims to make a measurement design of Information Security Management System by adopting the best practices based on information security standard defined by ISO / IEC.

About this research paper

What this paper is about

Information is an asset, such as important business assets, has value to an organization and consequently must be well protected. In organizations, information becomes an important and must remain available, and its existence should be maintained from unauthorized access. The use of information by unauthorized parties could be used for negative purposes which would be detrimental to the organization. Therefore, information security must be implemented correctly in order to avoid the impact of loss to the organization. Information security must satisfy the elements of confidentiality, integrity and availability. The international standard ISO / IEC 27000: 2014, SNI ISO / IEC 27001: 2013 and SNI ISO / IEC 27002: 2013 are a standard for Information Security Management System that can be used for the organization. These standard are able to test the security of the information and to measure the effectiveness of an implemented Information Security Management System (ISMS) which has been adopted as SNI ISO / IEC 27004: 2013. The standardization of Information Security Management Systems need an adjustment, the version of ISO / IEC 27004. The latter has adopted the development of ISO / IEC 27000, ISO / IEC 27001 and ISO / IEC 27002 which is required the measurement design of Information Security Management System. This study results in the design of the size of the Information Security Management System in accordance with the rules of international standards and the latest ISO standards. So it can be a reference for various organizations. This study aims to make a measurement design of Information Security Management System by adopting the best practices based on information security standard defined by ISO / IEC.

Why it matters

OpenAlex reports 16 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Information is an asset, such as important business assets, has value to an organization and consequently must be well protected. In organizations, information becomes an important and must remain available, and its existence should be maintained from unauthorized access. The use of information by unauthorized parties could be used for negative purposes which would be detrimental to the organization. Therefore, information security must be implemented correctly in order to avoid the impact of loss to the organization. Information security must satisfy the elements of confidentiality, integrity and availability. The international standard ISO / IEC 27000: 2014, SNI ISO / IEC 27001: 2013 and SNI ISO / IEC 27002: 2013 are a standard for Information Security Management System that can be used for the organization. These standard are able to test the security of the information and to measure the effectiveness of an implemented Information Security Management System (ISMS) which has been adopted as SNI ISO / IEC 27004: 2013. The standardization of Information Security Management Systems need an adjustment, the version of ISO / IEC 27004. The latter has adopted the development of ISO / IEC 27000, ISO / IEC 27001 and ISO / IEC 27002 which is required the measurement design of Information Security Management System. This study results in the design of the size of the Information Security Management System in accordance with the rules of international standards and the latest ISO standards. So it can be a reference for various organizations. This study aims to make a measurement design of Information Security Management System by adopting the best practices based on information security standard defined by ISO / IEC.

Key concepts: Information security management system, ITIL security management, Information security management, Certified Information Systems Security Professional, Information security, Computer security, Standard of Good Practice, Information security standards

Related papers

Back to paper searchBrowse research topicsOriginal source
The measurement design of information security management system — Research Paper | ScholarLens