DocumentCode :
3580899
Title :
The measurement design of information security management system
Author :
Nancylia, Merry ; Mudjtabar, Eddy K. ; Sutikno, Sarwono ; Rosmansyah, Yusep
Author_Institution :
Sch. of Electr. Eng. & Inf., Bandung Inst. of Technol., Bandung, Indonesia
fYear :
2014
Firstpage :
1
Lastpage :
5
Abstract :
Information is an asset, such as important business assets, has value to an organization and consequently must be well protected. In organizations, information becomes an important and must remain available, and its existence should be maintained from unauthorized access. The use of information by unauthorized parties could be used for negative purposes which would be detrimental to the organization. Therefore, information security must be implemented correctly in order to avoid the impact of loss to the organization. Information security must satisfy the elements of confidentiality, integrity and availability. The international standard ISO / IEC 27000: 2014, SNI ISO / IEC 27001: 2013 and SNI ISO / IEC 27002: 2013 are a standard for Information Security Management System that can be used for the organization. These standard are able to test the security of the information and to measure the effectiveness of an implemented Information Security Management System (ISMS) which has been adopted as SNI ISO / IEC 27004: 2013. The standardization of Information Security Management Systems need an adjustment, the version of ISO / IEC 27004. The latter has adopted the development of ISO / IEC 27000, ISO / IEC 27001 and ISO / IEC 27002 which is required the measurement design of Information Security Management System. This study results in the design of the size of the Information Security Management System in accordance with the rules of international standards and the latest ISO standards. So it can be a reference for various organizations. This study aims to make a measurement design of Information Security Management System by adopting the best practices based on information security standard defined by ISO / IEC.
Keywords :
security of data; IEC; ISMS; ISO standards; business assets; confidentiality; information security management system; information security standard; international standard ISO; international standards; measurement design; unauthorized access; IEC standards; ISO standards; Information security; Organizations; Standards organizations; effectiveness; information security; measurement; security management;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Telecommunication Systems Services and Applications (TSSA), 2014 8th International Conference on
Type :
conf
DOI :
10.1109/TSSA.2014.7065914
Filename :
7065914
Link To Document :
بازگشت