{"title":"Introduction of a Tool-Based Continuous Information Security Management System: An Exploratory Case Study","authors":"M. Brunner, Andrea Mussmann, R. Breu","doi":"10.1109/QRS-C.2018.00088","DOIUrl":null,"url":null,"abstract":"Tighter regulatory demands and higher customer expectations regarding the protection of information force enterprises to systematically ensure confidentiality, integrity and availability of stored information and processing facilities. Information Security Management Systems (ISMSs) are used to address these challenges. Recent studies show that the majority of companies plans to establish at least basic information security management to prepare for future developments. Larger enterprises have already embraced ISMSs, whereas small and medium-sized enterprises (SMEs) are catching up and require support in defining, introducing and operating them. We developed ADAMANT, an SME-friendly tool that supports continuous information security management incorporating stakeholders of different domains. In this paper, we evaluated our approach to introduce an ISMS in SMEs using an introductory information security training. The evaluation shows that our tool improves critical information security management tasks. Furthermore, integrating ADAMANT in customized security trainings allows companies to directly use training results to implement an ISMS.","PeriodicalId":199384,"journal":{"name":"2018 IEEE International Conference on Software Quality, Reliability and Security Companion (QRS-C)","volume":"15 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 IEEE International Conference on Software Quality, Reliability and Security Companion (QRS-C)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/QRS-C.2018.00088","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6
Abstract
Tighter regulatory demands and higher customer expectations regarding the protection of information force enterprises to systematically ensure confidentiality, integrity and availability of stored information and processing facilities. Information Security Management Systems (ISMSs) are used to address these challenges. Recent studies show that the majority of companies plans to establish at least basic information security management to prepare for future developments. Larger enterprises have already embraced ISMSs, whereas small and medium-sized enterprises (SMEs) are catching up and require support in defining, introducing and operating them. We developed ADAMANT, an SME-friendly tool that supports continuous information security management incorporating stakeholders of different domains. In this paper, we evaluated our approach to introduce an ISMS in SMEs using an introductory information security training. The evaluation shows that our tool improves critical information security management tasks. Furthermore, integrating ADAMANT in customized security trainings allows companies to directly use training results to implement an ISMS.