Risk-Based Information Security Audit Applied Research in the Power Industry
Gengshen Yu, Peng Gao
Abstract
Gengshen Yu, Peng Gao
Abstract
This paper analyzes the information security situation in the power industry, Combined with information security requirements of the power industry, From the information security audit objectives, audit evidence, information security control framework, information security and other aspects of the audit process is proposed for the power industry to establish risk-based information security audit systems and processes.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
This paper analyzes the information security situation in the power industry, Combined with information security requirements of the power industry, From the information security audit objectives, audit evidence, information security control framework, information security and other aspects of the audit process is proposed for the power industry to establish risk-based information security audit systems and processes.
Key concepts: Information security audit, Audit, Information security, Information security management, Information technology audit, Security controls, Security information and event management, Standard of Good Practice