首页> 外文会议>Americas conference on information systems >A Balanced Scorecard Approach to Evaluate Corporate Information Security Level and Suggestion of a Security Maturity Model
【24h】

A Balanced Scorecard Approach to Evaluate Corporate Information Security Level and Suggestion of a Security Maturity Model

机译:一种平衡的记分卡方法,可以评估企业信息安全级别和安全成熟度模型的建议

获取原文

摘要

This paper adopts a balanced scorecard (BSC) approach to evaluate corporate information security level. Numerous methodologies have been introduced in information security evaluation over last two decades. Each of those methodologies addresses various issues in the aspects of products, individuals, businesses, and nations such as security capability test guidelines for security products, information security level evaluation criteria for public organizations, information security management standard for businesses, etc. But, inconsistencies and redundancies between methodologies have hindered the wide spread use of evaluation methodologies, especially in Korea. As the first trial to establish systematic evaluation criteria, this paper presents a corporate information security evaluation methodology using a balanced scorecard. In addition, a security maturity model to classify the security level of businesses is presented.
机译:本文采用平衡的记分卡(BSC)方法来评估公司信息安全级别。在过去二十年中,在信息安全评估中介绍了许多方法。这些方法中的每一个都解决了安全产品的产品,个人,企业和国家的各个方面的各种问题,公共组织的信息安全级别评估标准,业务的信息安全管理标准等,但不一致和方法之间的冗余阻碍了评估方法的广泛普遍使用,特别是在韩国。作为建立系统评估标准的第一次试验,本文介绍了使用平衡计分卡的企业信息安全评估方法。此外,还提出了一种用于对业务安全级别进行分类的安全成熟度模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号