会议论文详细信息
1st Siliwangi International Conference on Innovation in Research 2018
Measuring effectiveness of control of information security management system based on SNI ISO/IEC 27004: 2013 standard
Aldya, A.P.^1 ; Sutikno, S.^2 ; Rosmansyah, Y.^2
Informatics Engineering Siliwangi University, Indonesia^1
School of Electrical Engineering and Informatics, Institute Technology of Bandung, Indonesia^2
关键词: Control groups;    Information security controls;    Information security management systems;    Information security managements;    ISO/IEC;    Measurement parameters;    Measurement process;    Standard documents;   
Others  :  https://iopscience.iop.org/article/10.1088/1757-899X/550/1/012020/pdf
DOI  :  10.1088/1757-899X/550/1/012020
来源: IOP
PDF
【 摘 要 】
One of the keys to the successful implementation of information security management in an organization is the selection and implementation of an information security management system control that is good and in accordance with the needs of the organization, the information security management system control can be adopted based on ISO/IEC 27001: 2013 standard document. To ensure the success of information security controls, it is necessary to measure the effectiveness of each control applied. SNI ISO/IEC 27004: 2013 is a standard that provides guidance on the development and use of measures and measurements to assess the effectiveness of controls and control groups in the information security management system as stated in the ISO/IEC 27001 standard, but to do the measurement process, required objects and measurement attributes and metrics, which are not explained in detail in the ISO ISO/IEC 27004: 2013 standard. This study aims to assist in measuring the effectiveness of information security management control by generating the flow of steps in determining the object and measurement parameters and the metrics used based on the provisions contained in the ISO ISO/IEC 27004: 2013 standard.
【 预 览 】
附件列表
Files Size Format View
Measuring effectiveness of control of information security management system based on SNI ISO/IEC 27004: 2013 standard 500KB PDF download
  文献评价指标  
  下载次数:3次 浏览次数:24次