The ISMS Business Environment Elaboration Using a UML Approach

  • Authors:
  • Andrzej Białas

  • Affiliations:
  • Institute of Control Systems, Długa 1-3, 41-506 Chorzów, Poland, e-mail: abialas@iss.pl

  • Venue:
  • Proceedings of the 2005 conference on Software Engineering: Evolution and Emerging Technologies
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

The paper deals with software development for supporting information security management, particularly the modeling of the business environment of the organization implementing Information Security Management System (ISMS). The ISMS, based on the PDCA (Plan-Do-Check-Act) model, was defined in the BS7799-2:2002 standard. The paper focuses on the identification of the ISMS business environment that provides appropriate positioning of the ISMS within the organization. The general model of the ISMS business environment based on the high-level risk analysis was presented. The UML approach allows to implement the ISMS within organizations in a more consistent and efficient way and to create supporting tools improving information security management.