Information security management: A hierarchical framework for various approaches

被引:39
作者
Eloff, MM [1 ]
von Solms, SH
机构
[1] Technikon Witwatersrand, Sch Informat Technol, Johannesburg, South Africa
[2] Rand Afrikaans Univ, Dept Comp Sci, Johannesburg, South Africa
关键词
certification; controls; standards; guidelines; code of practice; accreditation; benchmarking; self-assessment; legislation; evaluation criteria;
D O I
10.1016/S0167-4048(00)88613-7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The present article is aimed at clarifying the oft-times confusing terminology and at elucidating the various approaches obtaining to the realm of Information Security (IS) management. The IS management approaches selected for discussion in this article will specifically address those rudiments and concepts that play a key role in the assessment of the IS status of an organization. Following, a hierarchical framework will be developed in terms of which to elucidate ill-defined terms and concerts. By so doing, issues such as certification, benchmarking, guidelines and codes of practice will conic under consideration. IS management approahes widely accepted in the international arena. will also be mapped onto the said hierarchical framework.
引用
收藏
页码:243 / 256
页数:14
相关论文
共 21 条
[1]  
*BSI, 1999, BS799 BSI
[2]  
*BSI, 1995, BS7799 BSI
[3]  
*BSI, 1998, BS77 BSI 2
[4]  
*C CUR, 1998, BS7799
[5]  
*C CUR, 1999, FIRST C CIIR CERT PR
[6]  
*C CUR, 1999, BS7799 CCUR BSIDISC
[7]  
CAELLI WJ, 1994, P IFIP SEC 94 CUR
[8]  
*COBI, 1999, COBIT ADV
[9]  
*COBI, 1996, CONTR OBJ INF REL TE
[10]  
*GRAY, 1991, OP SYST BUS STRAT 19