{"title":"为组织的风险评估制定信息安全标准和措施","authors":"Prashant Manuja, R. Shekhawat","doi":"10.1080/09720529.2022.2075092","DOIUrl":null,"url":null,"abstract":"Abstract The absence of public safety normalization bodies can antagonistically affect the reception of worldwide security guidelines and best practices. This research is done for the benefit of people, process and technology for any organization. This paper presents a novel pragmatic network protection evaluation structure that is custom-made to the ISO 2700x standard necessities for the improvement of Information Security Management System (ISMS). This model can be utilized for both self-appraisal and examining/scoring instruments by public network protection specialists. Utilizing this model, associations can consider their current data security the broad frameworks in contrast to nearby and global guidelines by using worked in pre-review instruments. All things considered, the model will assist associations with assessing and improving their status for developing dangers and dangers. In this system, an original numerical model was likewise planned and carried out for the scoring/rating instrument, specifically, the public digital protection list (aeNCI). The aeNCI utilizes various boundaries to decide the development of existing network safety programs at public associations and produce a classification and correlation reports. The outcomes empowered the partner to confirm the security configuration of their frameworks and recognize possible attacks/hazard vectors.","PeriodicalId":46563,"journal":{"name":"JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY","volume":"25 1","pages":"1195 - 1202"},"PeriodicalIF":1.2000,"publicationDate":"2022-05-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Developing information security metrics and measures for risk assessment of an organization\",\"authors\":\"Prashant Manuja, R. Shekhawat\",\"doi\":\"10.1080/09720529.2022.2075092\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Abstract The absence of public safety normalization bodies can antagonistically affect the reception of worldwide security guidelines and best practices. This research is done for the benefit of people, process and technology for any organization. This paper presents a novel pragmatic network protection evaluation structure that is custom-made to the ISO 2700x standard necessities for the improvement of Information Security Management System (ISMS). This model can be utilized for both self-appraisal and examining/scoring instruments by public network protection specialists. Utilizing this model, associations can consider their current data security the broad frameworks in contrast to nearby and global guidelines by using worked in pre-review instruments. All things considered, the model will assist associations with assessing and improving their status for developing dangers and dangers. In this system, an original numerical model was likewise planned and carried out for the scoring/rating instrument, specifically, the public digital protection list (aeNCI). The aeNCI utilizes various boundaries to decide the development of existing network safety programs at public associations and produce a classification and correlation reports. The outcomes empowered the partner to confirm the security configuration of their frameworks and recognize possible attacks/hazard vectors.\",\"PeriodicalId\":46563,\"journal\":{\"name\":\"JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY\",\"volume\":\"25 1\",\"pages\":\"1195 - 1202\"},\"PeriodicalIF\":1.2000,\"publicationDate\":\"2022-05-19\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1080/09720529.2022.2075092\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q2\",\"JCRName\":\"MATHEMATICS, APPLIED\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1080/09720529.2022.2075092","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"MATHEMATICS, APPLIED","Score":null,"Total":0}
Developing information security metrics and measures for risk assessment of an organization
Abstract The absence of public safety normalization bodies can antagonistically affect the reception of worldwide security guidelines and best practices. This research is done for the benefit of people, process and technology for any organization. This paper presents a novel pragmatic network protection evaluation structure that is custom-made to the ISO 2700x standard necessities for the improvement of Information Security Management System (ISMS). This model can be utilized for both self-appraisal and examining/scoring instruments by public network protection specialists. Utilizing this model, associations can consider their current data security the broad frameworks in contrast to nearby and global guidelines by using worked in pre-review instruments. All things considered, the model will assist associations with assessing and improving their status for developing dangers and dangers. In this system, an original numerical model was likewise planned and carried out for the scoring/rating instrument, specifically, the public digital protection list (aeNCI). The aeNCI utilizes various boundaries to decide the development of existing network safety programs at public associations and produce a classification and correlation reports. The outcomes empowered the partner to confirm the security configuration of their frameworks and recognize possible attacks/hazard vectors.