Implementing the ISO/IEC 17799 standard in practice - findings from small and medium sized software organisations

T. Wiander
{"title":"Implementing the ISO/IEC 17799 standard in practice - findings from small and medium sized software organisations","authors":"T. Wiander","doi":"10.1109/SIIT.2007.4629320","DOIUrl":null,"url":null,"abstract":"The ISO/IEC 17799 standard is commonly viewed as a necessary element in information security management. However, there is no empirical evidence of the usefulness of the standard in practice. This paper analyses the implementation experiences of four organisations that have implemented the ISO/IEC 17799 standard. Through semi-structured interviews, the results of the study suggest that the implementation of the standard has increased the understanding of information security in all personnel groups and the understanding of security has broadened from the technical aspects to corporate security. As downsides of implementing the ISO/IEC 17799 standard, the difficulties in deploying the standard, and the readability of the standard were criticised. The standard was also criticised because it does not directly affect the quality of the end product or service; it only has an indirect effect owing to the improved information security practices.","PeriodicalId":126469,"journal":{"name":"2007 5th International Conference on Standardization and Innovation in Information Technology","volume":"19 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2007 5th International Conference on Standardization and Innovation in Information Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SIIT.2007.4629320","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5

Abstract

The ISO/IEC 17799 standard is commonly viewed as a necessary element in information security management. However, there is no empirical evidence of the usefulness of the standard in practice. This paper analyses the implementation experiences of four organisations that have implemented the ISO/IEC 17799 standard. Through semi-structured interviews, the results of the study suggest that the implementation of the standard has increased the understanding of information security in all personnel groups and the understanding of security has broadened from the technical aspects to corporate security. As downsides of implementing the ISO/IEC 17799 standard, the difficulties in deploying the standard, and the readability of the standard were criticised. The standard was also criticised because it does not directly affect the quality of the end product or service; it only has an indirect effect owing to the improved information security practices.
实施ISO/IEC 17799标准-中小型软件机构的调查结果
ISO/IEC 17799标准通常被视为信息安全管理的必要元素。然而,没有经验证据表明该标准在实践中有用。本文分析了四个实施ISO/IEC 17799标准的组织的实施经验。通过半结构化访谈,研究结果表明,标准的实施增加了所有人员群体对信息安全的理解,并且对安全的理解已经从技术方面扩展到企业安全。作为实施ISO/IEC 17799标准的缺点,部署标准的困难和标准的可读性受到了批评。该标准还受到批评,因为它没有直接影响最终产品或服务的质量;由于信息安全实践的改进,它只具有间接的影响。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信