DocumentCode :
3208454
Title :
A Database System for Effective Utilization of ISO/IEC 27002
Author :
Iqbal, Ahmad ; Horie, Daisuke ; Goto, Yuichi ; Cheng, Jingde
Author_Institution :
Dept. of Inf. & Comput. Sci., Saitama Univ., Saitama, Japan
fYear :
2009
fDate :
17-19 Dec. 2009
Firstpage :
607
Lastpage :
612
Abstract :
ISO/IEC 27002 is an international standard for information security management. Although many organizations need to manage their information systems according to ISO/IEC 27002, ISO/IEC 27002 is not convenient for users to retrieve terms, definitions, and security controls and to make documents for information security management because the ISO/IEC 27002 is distributed only in form of booklet or PDF. On the other hand, ISEE, an information security engineering environment, has been proposed to support all tasks in from requirement analysis to maintenance of security facilities of software/information systems. ISEDS, an information security engineering database system, as a main component of ISEE, is planed manage all ISO standards related with information security and their concerning documents. This paper presents a database system for effective utilization of ISO/IEC 27002 that is obtained by adding ISO/IEC 27002 and related documents into ISEDS. The paper analyzes usages of ISO/IEC 27002, gives requirement analysis of the database system, presents a design and construction of the database system, and shows a usage example. The paper also investigates a systematic method to construct databases of ISO standards for information security in ISEDS.
Keywords :
ISO standards; database management systems; security of data; software maintenance; systems analysis; ISEE; ISO standards; database system; effective ISO/IEC 27002 utilization; information security engineering environment; information security management; requirement analysis; Control systems; Data security; Database systems; IEC standards; ISO standards; Information analysis; Information management; Information retrieval; Information security; Management information systems; ISMS; ISO/IEC 27002; information security engineering environment; information security management;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Frontier of Computer Science and Technology, 2009. FCST '09. Fourth International Conference on
Conference_Location :
Shanghai
Print_ISBN :
978-0-7695-3932-4
Electronic_ISBN :
978-1-4244-5467-9
Type :
conf
DOI :
10.1109/FCST.2009.88
Filename :
5392854
Link To Document :
بازگشت