Vis enkel innførsel

dc.contributor.authorHaufe, Knut
dc.contributor.authorColomo-Palacios, Ricardo
dc.contributor.authorDzombeta, Srdan
dc.contributor.authorBrandis, Knud
dc.contributor.authorStantchev, Vladimir
dc.date.accessioned2018-10-08T10:50:00Z
dc.date.available2018-10-08T10:50:00Z
dc.date.created2016-12-28T20:50:14Z
dc.date.issued2016
dc.identifier.citationInternational journal of information systems and project management. 2016, 4 (4), 27-47.nb_NO
dc.identifier.issn2182-7796
dc.identifier.urihttp://hdl.handle.net/11250/2566831
dc.description.abstractSecuring sensitive organizational data has become increasingly vital to organizations. An Information Security Management System (ISMS) is a systematic approach for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an organization's information security. Key elements of the operation of an ISMS are ISMS processes. However, and in spite of its importance, an ISMS process framework with a description of ISMS processes and their interaction as well as the interaction with other management processes is not available in the literature. Cost benefit analysis of information security investments regarding single measures protecting information and ISMS processes are not in the focus of current research, mostly focused on economics. This article aims to fill this research gap by proposing such an ISMS process framework as the main contribution. It is based on a set of agreed upon ISMS processes in existing standards like ISO 27000 series, COBIT and ITIL. Within the framework, identified processes are described and their interaction and interfaces are specified. This framework helps to focus on the operation of the ISMS, instead of focusing on measures and controls. By this, as a main finding, the systemic character of the ISMS consisting of processes and the perception of relevant roles of the ISMS is strengthened.nb_NO
dc.language.isoengnb_NO
dc.subjectInformation securitynb_NO
dc.subjectIT security managementnb_NO
dc.subjectISMSnb_NO
dc.subjectProcess frameworknb_NO
dc.titleA process framework for information security managementnb_NO
dc.typeJournal articlenb_NO
dc.typePeer reviewednb_NO
dc.description.versionpublishedVersionnb_NO
dc.subject.nsiVDP::Teknologi: 500::Informasjons- og kommunikasjonsteknologi: 550nb_NO
dc.source.pagenumber27-47nb_NO
dc.source.volume4nb_NO
dc.source.journalInternational journal of information systems and project managementnb_NO
dc.source.issue4nb_NO
dc.identifier.doi10.12821/ijispm040402
dc.identifier.cristin1417844
cristin.unitcode224,55,0,0
cristin.unitnameAvdeling for informasjonsteknologi
cristin.ispublishedtrue
cristin.fulltextoriginal
cristin.qualitycode1


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel