Title :
Appraisal of the Effectiveness and Efficiency of an Information Security Management System Based on ISO 27001
Author :
Boehmer, Wolfgang
Author_Institution :
Dep. of Comput. Sci., Tech. Univ. Darmstadt, Darmstadt
Abstract :
The ISO27001:2005, as an information security management system (ISMS), is establishing itself more and more as the security standard in enterprises. In 2008 more than 4457 certified enterprises could be registered worldwide. Nevertheless, the registering an ISMS still says nothing about the quality and performance of its implementation. Therefore, in this article, a method for measuring the performance of the implementation and operation of an ISMS is presented.
Keywords :
ISO standards; security of data; ISMS; ISO 27001; ISO27001:2005; information security management system; Appraisal; Computer science; Computer security; Conference management; Documentation; ISO standards; Information management; Information security; Risk management; Technology management; ISMS; ISO 27001; effectiveness; efficiency; strategic dilemma;
Conference_Titel :
Emerging Security Information, Systems and Technologies, 2008. SECURWARE '08. Second International Conference on
Conference_Location :
Cap Esterel
Print_ISBN :
978-0-7695-3329-2
Electronic_ISBN :
978-0-7695-3329-2
DOI :
10.1109/SECURWARE.2008.7