Method for Evaluating Information Security Level in Organisations
Mari Seeba, Sten Mäses, Raimundas Matulevičius
Abstract
Open-access reader
Mari Seeba, Sten Mäses, Raimundas Matulevičius
Abstract
Open-access reader
Abstract This paper introduces a method for evaluating information security levels of organisations using a developed framework. The framework is based on Estonian Information Security Standard categories which is compatible with ISO 27001 standard. The framework covers both technical and organisational aspects of information security. The results provide an overview of security to the organisation’s management, compare different organisations across the region, and support strategic decision-making on a national level.
OpenAlex reports 4 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Abstract This paper introduces a method for evaluating information security levels of organisations using a developed framework. The framework is based on Estonian Information Security Standard categories which is compatible with ISO 27001 standard. The framework covers both technical and organisational aspects of information security. The results provide an overview of security to the organisation’s management, compare different organisations across the region, and support strategic decision-making on a national level.
Key concepts: Information security management system, Standard of Good Practice, Information security, Information security management, Information systems security, ITIL security management, Information security standards, Security management