Challenging IS and ISM Standardization for Business Benefits

J. Anttila, J. Kajava
{"title":"Challenging IS and ISM Standardization for Business Benefits","authors":"J. Anttila, J. Kajava","doi":"10.1109/ARES.2010.113","DOIUrl":null,"url":null,"abstract":"This paper deals with challenges of the Information Security (IS) and Information Security Management (ISM) standards and their beneficial use in organizations. Emphasis is in the standardization within the committee ISO/IEC JTC1/SC27 and in its management standardization. It is also considered ISM standards’ complicated links with many other management standards. Principles, concepts and definitions are not considered consistently in the ISM standards. ISM standards use the recognized business management models very superficially. Standards do not make clear relations between ISM and Information Security Assurance (ISA). A real crisis in the ISM standardization is that it has no innovative solutions for modern business environments that emphasize speed, changes, agility, and complexity.The situational knowledge for the paper is based on worldwide observations by the authors through collaboration with many different contexts, organizations and expert networks. The paper provides a practical business-dedicated approach to the issue and brings together a business practitioner and an information security researcher knowing by long-standing experiences the real difficulties and possibilities in organizations. Recognized researchers have been referred for the links to sound multifaceted theoretical foundations.","PeriodicalId":360339,"journal":{"name":"2010 International Conference on Availability, Reliability and Security","volume":"6 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2010-03-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2010 International Conference on Availability, Reliability and Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ARES.2010.113","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

This paper deals with challenges of the Information Security (IS) and Information Security Management (ISM) standards and their beneficial use in organizations. Emphasis is in the standardization within the committee ISO/IEC JTC1/SC27 and in its management standardization. It is also considered ISM standards’ complicated links with many other management standards. Principles, concepts and definitions are not considered consistently in the ISM standards. ISM standards use the recognized business management models very superficially. Standards do not make clear relations between ISM and Information Security Assurance (ISA). A real crisis in the ISM standardization is that it has no innovative solutions for modern business environments that emphasize speed, changes, agility, and complexity.The situational knowledge for the paper is based on worldwide observations by the authors through collaboration with many different contexts, organizations and expert networks. The paper provides a practical business-dedicated approach to the issue and brings together a business practitioner and an information security researcher knowing by long-standing experiences the real difficulties and possibilities in organizations. Recognized researchers have been referred for the links to sound multifaceted theoretical foundations.
为企业利益挑战信息系统和管理系统标准化
本文讨论了信息安全(IS)和信息安全管理(ISM)标准面临的挑战及其在组织中的有益应用。重点是ISO/IEC JTC1/SC27委员会内的标准化及其管理标准化。它也被认为是ISM标准与许多其他管理标准的复杂联系。ISM标准中考虑的原则、概念和定义不一致。ISM标准非常肤浅地使用公认的业务管理模型。标准没有明确ISM和ISA (Information Security Assurance)之间的关系。ISM标准化的一个真正危机是,它没有针对强调速度、变化、敏捷性和复杂性的现代业务环境的创新解决方案。本文的情境知识是基于作者通过与许多不同的背景、组织和专家网络合作而进行的全球观察。本文提供了一种实用的业务专用方法来解决这个问题,并汇集了一位业务实践者和一位信息安全研究人员,他们通过长期的经验了解组织中的实际困难和可能性。公认的研究人员已经提到了链接健全的多方面的理论基础。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信