A quantitative method for ISO 17799 gap analysis

Yükleniyor...
Küçük Resim

Tarih

Dergi Başlığı

Dergi ISSN

Cilt Başlığı

Yayıncı

Elsevier Advanced Technology

Erişim Hakkı

info:eu-repo/semantics/closedAccess

Özet

ISO/AEC 17799:2005 is one of the leading standards of information security. It is the code of practice including 133 controls in 11 different domains. There are a number of tools and software that are used by organizations to check whether they comply with this standard. The task of checking compliance helps organizations to determine their conformity to the controls listed in the standard and deliver useful outputs to the certification process. In this paper, a quantitative survey method is proposed for evaluating ISO 17799 compliance. Our case study has shown that the survey method gives accurate compliance results in a short time with minimized cost. (C) 2006 Elsevier Ltd. All rights reserved.

Açıklama

Anahtar Kelimeler

BS 7799, ISO 17799, ISO 27001, compliance, information security, risk analysis, quantitative risk analysis, survey

Kaynak

Computers & Security

WoS Q Değeri

Scopus Q Değeri

Cilt

25

Sayı

6

Künye

Onay

İnceleme

Ekleyen

Referans Veren