Search results

1 – 10 of over 1000
Open Access
Article
Publication date: 12 November 2018

Stefan Fenz and Thomas Neubauer

The purpose of this paper is to provide a method to formalize information security control descriptions and a decision support system increasing the automation level and…

3624

Abstract

Purpose

The purpose of this paper is to provide a method to formalize information security control descriptions and a decision support system increasing the automation level and, therefore, the cost efficiency of the information security compliance checking process. The authors advanced the state-of-the-art by developing and applying the method to ISO 27002 information security controls and by developing a semantic decision support system.

Design/methodology/approach

The research has been conducted under design science principles. The formalized information security controls were used in a compliance/risk management decision support system which has been evaluated with experts and end-users in real-world environments.

Findings

There are different ways of obtaining compliance to information security standards. For example, by implementing countermeasures of different quality depending on the protection needs of the organization. The authors developed decision support mechanisms which use the formal control descriptions as input to support the decision-maker at identifying the most appropriate countermeasure strategy based on cost and risk reduction potential.

Originality/value

Formalizing and mapping the ISO 27002 controls to the security ontology enabled the authors to automatically determine the compliance status and organization-wide risk-level based on the formal control descriptions and the modelled environment, including organizational structures, IT infrastructure, available countermeasures, etc. Furthermore, it allowed them to automatically determine which countermeasures are missing to ensure compliance and to decrease the risk to an acceptable level.

Details

Information & Computer Security, vol. 26 no. 5
Type: Research Article
ISSN: 2056-4961

Keywords

Content available
1338

Abstract

Details

Benchmarking: An International Journal, vol. 13 no. 1/2
Type: Research Article
ISSN: 1463-5771

Content available
Article
Publication date: 1 September 2004

Alex M. Andrew

86

Abstract

Details

Kybernetes, vol. 33 no. 8
Type: Research Article
ISSN: 0368-492X

Keywords

Content available
Article
Publication date: 13 March 2007

45

Abstract

Details

Industrial Robot: An International Journal, vol. 34 no. 2
Type: Research Article
ISSN: 0143-991X

Content available
Article
Publication date: 16 January 2007

47

Abstract

Details

Industrial Robot: An International Journal, vol. 34 no. 1
Type: Research Article
ISSN: 0143-991X

Content available
Article
Publication date: 3 April 2007

37

Abstract

Details

Sensor Review, vol. 27 no. 2
Type: Research Article
ISSN: 0260-2288

Content available
Article
Publication date: 1 November 2006

89

Abstract

Details

Industrial Robot: An International Journal, vol. 33 no. 6
Type: Research Article
ISSN: 0143-991X

Content available
Article
Publication date: 8 May 2007

60

Abstract

Details

Industrial Robot: An International Journal, vol. 34 no. 3
Type: Research Article
ISSN: 0143-991X

Content available
Article
Publication date: 24 April 2007

64

Abstract

Details

Assembly Automation, vol. 27 no. 2
Type: Research Article
ISSN: 0144-5154

Content available
Article
Publication date: 27 February 2007

59

Abstract

Details

Assembly Automation, vol. 27 no. 1
Type: Research Article
ISSN: 0144-5154

1 – 10 of over 1000