• DocumentCode
    3050101
  • Title

    Analysis of Strongly and Weakly Coupled Management Systems in Information Security

  • Author

    Boehmer, Wolfgang

  • Author_Institution
    Tech. Univ. Darmstadt, Darmstadt, Germany
  • fYear
    2010
  • fDate
    18-25 July 2010
  • Firstpage
    109
  • Lastpage
    116
  • Abstract
    In an effort to enhance enterprise security, three standard management systems have been established as applications of the Deming cycle: the Information Security Management System (ISMS) in accordance with the ISO 27001 standard, the Business Continuity Management System (BCM) in accordance with the BS 25999 standard and the Information Technology Service Management System (ITSM) in accordance with the ISO 20000 standard. These three management systems have been developed to operate independent of one another, but are often used together within a given company. It can be shown that management systems modeled after the Deming cycle behave as bisimulations with dynamic feedback policies and can be expressed formally as control circuits within the Discrete Event Systems (DES) theory. In this article, we present an analytical description of the optimal structure through which the three management systems (ISMS, BCMS, and ITSM) should be linked in a company. We define a coupling parameter and, using an equation for the discrete control loop, show that ISMS and ITSM should ideally be strongly coupled, and ISMS and BCMS should be weakly coupled.
  • Keywords
    ISO standards; discrete event systems; information systems; security of data; BS 25999 standard; Deming cycle; ISO 20000 standard; ISO 27001 standard; bisimulations behavior; business continuity management system; coupling parameter; discrete control loop; discrete event systems theory; information security management system; information technology service management system; strongly coupled management system; weakly coupled management system; Actuators; Automata; Companies; ISO standards; Process control; Security; bisimulation; control loop; control systems engineering; coupled management systems; dynamic policies; strong/weak coupling;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Emerging Security Information Systems and Technologies (SECURWARE), 2010 Fourth International Conference on
  • Conference_Location
    Venice
  • Print_ISBN
    978-1-4244-7517-9
  • Electronic_ISBN
    978-0-7695-4095-5
  • Type

    conf

  • DOI
    10.1109/SECURWARE.2010.26
  • Filename
    5633657