An application of integral engineering technique to information security standards analysis and refinement

  • Authors:
  • Dmitry V. Cheremushkin;Alexander V. Lyubimov

  • Affiliations:
  • National Research University of Information Technologies, Mechanics and Optics, Saint-Petersburg, Russian Federation;Saint-Petersburg State Polytechnical University, Saint-Petersburg, Russian Federation

  • Venue:
  • Proceedings of the 3rd international conference on Security of information and networks
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

The work demonstrates practical application of information security integral engineering technique to solve standards analysis and refinement problem. The application was exemplified by the development and analysis of the ISMS standards (ISO/IEC 27000 series) dictionary object model. Standards refinement process consisting of model development, model and standards modification was described. As a result of the research the weaknesses related to "Asset", "Risk management", "Information security policy" and "Certification document" concepts were revealed and proposals on their elimination were formulated. The paper shows that semiformal modeling techniques can be successfully applied and efficiently used to analyze and amend international standards.