DocumentCode :
1958352
Title :
Challenging IS and ISM Standardization for Business Benefits
Author :
Anttila, Juhani ; Kajava, Jorma
Author_Institution :
Quality Integration, Helsinki, Finland
fYear :
2010
fDate :
15-18 Feb. 2010
Firstpage :
416
Lastpage :
421
Abstract :
This paper deals with challenges of the Information Security (IS) and Information Security Management (ISM) standards and their beneficial use in organizations. Emphasis is in the standardization within the committee ISO/IEC JTC1/SC27 and in its management standardization. It is also considered ISM standards´ complicated links with many other management standards. Principles, concepts and definitions are not considered consistently in the ISM standards. ISM standards use the recognized business management models very superficially. Standards do not make clear relations between ISM and Information Security Assurance (ISA). A real crisis in the ISM standardization is that it has no innovative solutions for modern business environments that emphasize speed, changes, agility, and complexity.The situational knowledge for the paper is based on worldwide observations by the authors through collaboration with many different contexts, organizations and expert networks. The paper provides a practical business-dedicated approach to the issue and brings together a business practitioner and an information security researcher knowing by long-standing experiences the real difficulties and possibilities in organizations. Recognized researchers have been referred for the links to sound multifaceted theoretical foundations.
Keywords :
IEC standards; ISO standards; commerce; organisational aspects; security of data; standardisation; IS standardization; ISM standardization; ISO/IEC JTC1/SC27 standards; business benefits; business-dedicated approach; information security assurance; information security management; management standards; organization use; Availability; Crisis management; IEC standards; ISO standards; Information management; Information security; Packaging; Standardization; Standards organizations; Standards publication;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Availability, Reliability, and Security, 2010. ARES '10 International Conference on
Conference_Location :
Krakow
Print_ISBN :
978-1-4244-5879-0
Type :
conf
DOI :
10.1109/ARES.2010.113
Filename :
5438059
Link To Document :
بازگشت