DocumentCode
3050101
Title
Analysis of Strongly and Weakly Coupled Management Systems in Information Security
Author
Boehmer, Wolfgang
Author_Institution
Tech. Univ. Darmstadt, Darmstadt, Germany
fYear
2010
fDate
18-25 July 2010
Firstpage
109
Lastpage
116
Abstract
In an effort to enhance enterprise security, three standard management systems have been established as applications of the Deming cycle: the Information Security Management System (ISMS) in accordance with the ISO 27001 standard, the Business Continuity Management System (BCM) in accordance with the BS 25999 standard and the Information Technology Service Management System (ITSM) in accordance with the ISO 20000 standard. These three management systems have been developed to operate independent of one another, but are often used together within a given company. It can be shown that management systems modeled after the Deming cycle behave as bisimulations with dynamic feedback policies and can be expressed formally as control circuits within the Discrete Event Systems (DES) theory. In this article, we present an analytical description of the optimal structure through which the three management systems (ISMS, BCMS, and ITSM) should be linked in a company. We define a coupling parameter and, using an equation for the discrete control loop, show that ISMS and ITSM should ideally be strongly coupled, and ISMS and BCMS should be weakly coupled.
Keywords
ISO standards; discrete event systems; information systems; security of data; BS 25999 standard; Deming cycle; ISO 20000 standard; ISO 27001 standard; bisimulations behavior; business continuity management system; coupling parameter; discrete control loop; discrete event systems theory; information security management system; information technology service management system; strongly coupled management system; weakly coupled management system; Actuators; Automata; Companies; ISO standards; Process control; Security; bisimulation; control loop; control systems engineering; coupled management systems; dynamic policies; strong/weak coupling;
fLanguage
English
Publisher
ieee
Conference_Titel
Emerging Security Information Systems and Technologies (SECURWARE), 2010 Fourth International Conference on
Conference_Location
Venice
Print_ISBN
978-1-4244-7517-9
Electronic_ISBN
978-0-7695-4095-5
Type
conf
DOI
10.1109/SECURWARE.2010.26
Filename
5633657
Link To Document