Yayınlanmış 1 Ocak 2010 | Sürüm v1
Konferans bildirisi Açık

A Collaborative Process Based Risk Analysis for Information Security Management Systems

  • 1. TUBITAK, Ankara, Turkey
  • 2. METU, Ankara, Turkey

Açıklama

Today, many organizations quote intent for ISO/IEC 27001:2005 certification. Also, some organizations are en route to certification or already certified. Certification process requires performing a risk analysis in the specified scope. Risk analysis is a challenging process especially when the topic is information security. Today, a number of methods and tools are available for information security risk analysis. The hard task is to use the best fit for the certification. In this work we have proposed a process based risk analysis method which is suitable for ISO/IEC 27001:2005 certifications. Our risk analysis method allows the participation of staff to the determination of the scope and provides a good fit for the certification process. The proposed method has been conducted for an organization and the results of the applications are shared with the audience. The proposed collaborative risk analysis method allows for the participation of staff and managers while still being manageable in a timely manner to uncover crucial information security risks.

Dosyalar

bib-aa3d05a0-fb87-4412-b4cb-abb4dfcc14ad.txt

Dosyalar (206 Bytes)

Ad Boyut Hepisini indir
md5:255a0f29cdc3ef70c4f4c03ac8875ea5
206 Bytes Ön İzleme İndir