Designing a process reference model for information security management systems

6Citations
Citations of this article
17Readers
Mendeley users who have this article in their library.
Get full text

Abstract

In spite of growing interest for information security, the adoption of the international standard on information security management (ISO/IEC 27001) is still very low. This standard provides requirements to manage an Information Security Management System. We argue that this standard is too complex to be directly implemented by small structures such as SMEs. We thus propose a process model that aims to describe the processes involved in information security management and facilitate adoption. In order to do this, we reuse process model previously derived from ISO/IEC 20000-1, which is also a management system standard but developed for IT Service Management. In this paper, we determine the generic management system requirements and their corresponding processes by mapping the requirements from ISO/IEC 20000-1 and ISO/IEC 27001 standards. At last, we create the information security specific processes with the remaining ISO/IEC 27001 requirements, and we conclude with the possible uses of the process model. © 2012 Springer-Verlag.

Cite

CITATION STYLE

APA

Mangin, O., Barafort, B., Heymans, P., & Dubois, E. (2012). Designing a process reference model for information security management systems. In Communications in Computer and Information Science (Vol. 290 CCIS, pp. 129–140). https://doi.org/10.1007/978-3-642-30439-2_12

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free