Definition of Security Practices in STP for SLMM
Tai-hoon Kim
Abstract
Tai-hoon Kim
Abstract
To manage security level of information system (IS), organizations must select security practices (SP) first, and then apply them according to security level. SP can be divided into 2 groups security management part (SMP) and security technology part (STP), and some SPs in SMP were proposed already by Drs. Tai-hoon Kim and Kouichi Sakurai [1]. In this paper, we propose some SPs in STP to construct STP for Security Level Management Model (SLMM). 1. Security Level Management and Security Practices [1] Security level management is the activity to sustain the security level which defined as an essential one by considering operational environments of information systems. So security level management is not the check of temporary status in short time but the continuous observation to the variable environment. To perform the security level management, all factors related to the operation of information system should be considered, and by doing so, security of whole information systems can be managed. But because of the limitation occurred by some reasons, all factors can not be managed by same level. To overcome this problem,
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
To manage security level of information system (IS), organizations must select security practices (SP) first, and then apply them according to security level. SP can be divided into 2 groups security management part (SMP) and security technology part (STP), and some SPs in SMP were proposed already by Drs. Tai-hoon Kim and Kouichi Sakurai [1]. In this paper, we propose some SPs in STP to construct STP for Security Level Management Model (SLMM). 1. Security Level Management and Security Practices [1] Security level management is the activity to sustain the security level which defined as an essential one by considering operational environments of information systems. So security level management is not the check of temporary status in short time but the continuous observation to the variable environment. To perform the security level management, all factors related to the operation of information system should be considered, and by doing so, security of whole information systems can be managed. But because of the limitation occurred by some reasons, all factors can not be managed by same level. To overcome this problem,
Key concepts: Security information and event management, Security service, Security convergence, Security through obscurity, Cloud computing security, Security management, Computer security, Computer security model