Abstract
Information security is a very important component in the context of an organization's dependence on ICT. The operational environment where these technologies are operating is a very complex one. Offering a good level of protection by information security process needs a well defined managerial framework. This paper discusses the reasons why having a well defined managerial security framework is needed in an information security area, as well as which are the tools to build and implement such a management framework. After a short presentation, two international standards related to Information Security Management, the ISO 17799:2005 and ISO 27001 standards, and the implications of being conforming to these standards are analysed and their advantages and limits in a security management framework are pointed out.
Author supplied keywords
Cite
CITATION STYLE
Tashi, I., & Ghernaouti-Hélie, S. (2007). Iso security standards as a leverage on it security management. In Association for Information Systems - 13th Americas Conference on Information Systems, AMCIS 2007: Reaching New Heights (Vol. 1, pp. 437–448).
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.