Title :
Corporate Security Compliance in a Heterogeneous Environment
Author :
Yip, Frederick ; Wong, Alfred Ka yiu ; Ray, Pradeep ; Paramesh, Nanda
Author_Institution :
Sch. of Inf. Syst., Technol. & Manage., New South Wales Univ.
Abstract :
Organizations often have to audit and assess their information system security as a corporate compliance process based on a range of standards. The growing number of security standards such as CobiT, ISO17799 and BSI raises the potential interoperability problem in a heterogeneous environment. Often different standards are needed to satisfy different regional regulatory and obligatory requirements. In this paper, we present an ontology based approach to deal with the interoperability problem
Keywords :
BSI standards; ISO standards; commerce; open systems; security of data; BSI security standard; CobiT security standard; ISO17799 security standard; corporate compliance process; corporate security compliance; heterogeneous environment; information system security; interoperability problem; obligatory requirement; ontology based approach; regional regulatory requirement; Ontologies; Radiofrequency interference; Security; assessment; ontology; security compliance;
Conference_Titel :
Network Operations and Management Symposium, 2006. NOMS 2006. 10th IEEE/IFIP
Conference_Location :
Vancouver, BC
Print_ISBN :
1-4244-0142-9
DOI :
10.1109/NOMS.2006.1687637