首页> 外文会议>International Conference on Information Technology Systems and Innovation >Design of information security risk management using ISO/IEC 27005 and NIST SP 800-30 revision 1: A case study at communication data applications of XYZ institute
【24h】

Design of information security risk management using ISO/IEC 27005 and NIST SP 800-30 revision 1: A case study at communication data applications of XYZ institute

机译:使用ISO / IEC 27005和NIST SP 800-30修订版1的信息安全风险管理设计:XYZ研究所通信数据应用案例研究

获取原文

摘要

Information security is a priority for the organization. Information can be carried as critical assets, because it's advocated a national security. Communication data applications in the XYZ Institute advocated national security. However, it has amounted vulnerabilities and threats at their information systems and networks. With vulnerabilities and threat which give impact, appears an information security risk for their organization. This causes the organization needs information security risk management process for communication data applications in XYZ Institute. To Implement design of information security risk management for communication data applications in XYZ Institute, we used ISO 27005 framework and NIST SP 800-30 revision 1 as a guideline to risk assessment, and ISO 27002 as reference to development risk treatment plan. The result of this research is how to implementation a design of information security risk management at communication data applications in XYZ Institute.
机译:信息安全是组织的首要任务。信息可以作为重要资产携带,因为它倡导国家安全。 XYZ研究所的通信数据应用程序倡导国家安全。但是,它已经在其信息系统和网络上造成了漏洞和威胁。漏洞和威胁会产生影响,因此对其组织构成信息安全风险。这导致组织需要在XYZ Institute中对通信数据应用程序进行信息安全风险管理过程。为了在XYZ研究所实施用于通信数据应用程序的信息安全风险管理设计,我们使用了ISO 27005框架和NIST SP 800-30版本1作为风险评估的指南,并使用ISO 27002作为发展风险处理计划的参考。这项研究的结果是如何在XYZ研究所的通信数据应用程序中实现信息安全风险管理的设计。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号