• DocumentCode
    3335175
  • Title

    An assessment model of information security implementation levels

  • Author

    Stambul, M.A.M. ; Razali, Rozilawati

  • Author_Institution
    Centre of Software Technol. & Manage., Univ. Kebangsaan Malaysia, Bangi, Malaysia
  • fYear
    2011
  • fDate
    17-19 July 2011
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Information security is very important as it serves to protect an organisation from any threats and risks by ensuring the information is always safe to be accessed, reliable and confidentially protected. In order to ensure information security, organisations normally introduce policies and guidelines which are made available to all members. Despite this effort however, security threats on organisations´ information still occur. One of the reasons is because organisations are not aware of the information security levels that they practise. This paper discusses a measurement model for assessing information security implementation levels in organisations. The model consists of three maturity levels that determine the degrees of which information security is addressed in an organisation. The levels contain several factors that are necessary for ensuring information security. The study used Systematic Literature Review (SLR) as the instruments to determine the appropriate measurement parameters. The identified parameters were combined with general models and measurement standards of information security. The model can be used by organisations to determine their levels of maturity in ensuring the security of their information. This enables them to improve their current information security practices.
  • Keywords
    security of data; assessment model; general models; information security implementation levels; information security measurement standards; maturity levels; measurement model; organization information protection; security threats; systematic literature review; Capability maturity model; ISO standards; Information security; Modeling; Risk management; information security; maturity model; measurement; security level;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Electrical Engineering and Informatics (ICEEI), 2011 International Conference on
  • Conference_Location
    Bandung
  • ISSN
    2155-6822
  • Print_ISBN
    978-1-4577-0753-7
  • Type

    conf

  • DOI
    10.1109/ICEEI.2011.6021561
  • Filename
    6021561