Development of an integrated, risk-based platform for information and e-services security

  • Authors:
  • Andrzej Białas

  • Affiliations:
  • Institute of Control Systems, Chorzów, Długa 1-3, Poland

  • Venue:
  • SAFECOMP'06 Proceedings of the 25th international conference on Computer Safety, Reliability, and Security
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

The paper presents a risk-based integrated platform for the information and e-services security management related to the Information Security Managements System (ISMS) concept. The current state of the work is shown, including the UML-based methodology, and the incrementally developed computer-aided tool prototype. The assumptions of the integrated platform can be specified on the basis of sampled experiences from the first deployment and case studies, an analysis of standards, legal requirements and technology, and a study of the needs and requirements of various organizations. It is assumed that the common and enhanced assets inventory will integrate information security, business continuity and IT services management processes. The paper concludes the current, initial state of the work and defines its further directions.