首页> 外文会议>12th Americas Conference on Information Systems(AMCIS 2006) vol.2 >A Process Approach to Information Security: Lessons from Quality Management
【24h】

A Process Approach to Information Security: Lessons from Quality Management

机译:信息安全的过程方法:质量管理的经验教训

获取原文
获取原文并翻译 | 示例

摘要

The prevalent approach to analysis of information security is typically event-centric and ad-hoc based primarily on risk management principles. However, we believe that scholars and practitioners in the information security field can benefit significantly from the experiences and principles of quality management, where process orientation dominates and continuous improvement is the essence. This paper reviews some key concepts in quality management and draws lessons for information security management. Based on this, a process-centric framework for managing information security is developed. The framework is then explored in the context of root-cause analysis of realized threats or security breaches. Future research directions are then suggested.
机译:信息安全分析的普遍方法通常以事件为中心,并且主要基于风险管理原则进行临时性的研究。但是,我们认为,信息安全领域的学者和实践者可以从质量管理的经验和原则中受益匪浅,在这些经验和原则中,过程导向占主导地位,持续改进是本质。本文回顾了质量管理中的一些关键概念,并为信息安全管理吸取了教训。基于此,开发了以流程为中心的信息安全管理框架。然后,在对已实现的威胁或安全漏洞进行根本原因分析的上下文中探索该框架。然后提出了未来的研究方向。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号