Applying ISO 17799:2005 in information security management
Ming Chang Lee, To Chang
Abstract
Ming Chang Lee, To Chang
Abstract
In this paper, we discussed ISO 17799:2005 control, process, and security organisation structure. According to the results, the code of practice for information security management includes: capture the processes for implementing information security management in organisational Information Security Management System (ISMS), provide an organisational security structure to assess the extent information security management efforts, provide a comprehensive framework for ensuring the effectiveness of information security control over the information sources that support operations and assets. A case example (National Tax Administration Southern Taiwan Province) of an organisational security management, including organisational security structure, ISMS plan-do-check-act cycle, and information asset assessment management are discussed.
OpenAlex reports 9 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
In this paper, we discussed ISO 17799:2005 control, process, and security organisation structure. According to the results, the code of practice for information security management includes: capture the processes for implementing information security management in organisational Information Security Management System (ISMS), provide an organisational security structure to assess the extent information security management efforts, provide a comprehensive framework for ensuring the effectiveness of information security control over the information sources that support operations and assets. A case example (National Tax Administration Southern Taiwan Province) of an organisational security management, including organisational security structure, ISMS plan-do-check-act cycle, and information asset assessment management are discussed.
Key concepts: Information security management, Certified Information Security Manager, Security information and event management, Information security management system, ITIL security management, Asset (computer security), Information security, Security management