Sector-Based Improvement of the Information Security Risk Management Process in the Context of Telecommunications Regulation

7Citations
Citations of this article
13Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The current European regulation on public communications networks requires today that Telecommunications Service Providers (TSPs) take appropriate technical and organizational measures to manage the risks posed to security of networks and services. However, a key issue in this process is the risk identification activity, which roughly consists in defining what are the relevant risks regarding the business operated and the architecture in place. The same problem appears when selecting relevant security controls. The research question discussed in this paper is: how to adapt generic Information Security Risk Management (ISRM) process and practices to the telecommunications sector? To answer this research question, a four-step research method has been established and is presented in this paper. The outcome is an improved ISRM process in the context of the telecommunications regulation. © Springer-Verlag Berlin Heidelberg 2013.

Cite

CITATION STYLE

APA

Mayer, N., Aubert, J., Cholez, H., & Grandry, E. (2013). Sector-Based Improvement of the Information Security Risk Management Process in the Context of Telecommunications Regulation. In Communications in Computer and Information Science (Vol. 364 CCIS, pp. 13–24). Springer Verlag. https://doi.org/10.1007/978-3-642-39179-8_2

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free