Title :
Assessment of enterprise information security - the importance of prioritization $
Author :
Johansson, Erik ; Johnson, Pontus
Author_Institution :
Dept. of Ind. Inf. and Control Syst., R. Inst. of Technol., Sweden
Abstract :
Assessing the level of information security in an enterprise is a serious challenge for many organizations. This paper considers the prioritization of the field of enterprise information security. The paper thus considers how we may know what parts of information security are important for a company to address and what parts are not. Two methods for prioritization are used. The results demonstrate to what extent different standards committees, guideline authors and expert groups differ in their opinions on what the important issues are in enterprise information security. The ISO/IEC 17799, the NIST SP 800-26, the ISF standards committees, the CMU/SEI OCTAVE framework authors and an expert panel at the Swedish Information Processing Society (DFS) are considered. The differences in prioritization have important consequences on enterprise information security assessments. The effects on the information security assessment results in a European energy company are presented in the paper.
Keywords :
IEC standards; ISO standards; business data processing; security of data; CMU/SEI OCTAVE framework; ISF standards; ISO/IEC 17799; NIST SP 800-26; Swedish Information Processing Society; enterprise information security assessment; prioritization; Companies; Decision making; Electrical equipment industry; Guidelines; IEC standards; ISO standards; Industrial control; Information security; Management information systems; Tree data structures;
Conference_Titel :
EDOC Enterprise Computing Conference, 2005 Ninth IEEE International
Conference_Location :
Enschede
Print_ISBN :
0-7695-2441-9
DOI :
10.1109/EDOC.2005.9