DocumentCode :
3050101
Title :
Analysis of Strongly and Weakly Coupled Management Systems in Information Security
Author :
Boehmer, Wolfgang
Author_Institution :
Tech. Univ. Darmstadt, Darmstadt, Germany
fYear :
2010
fDate :
18-25 July 2010
Firstpage :
109
Lastpage :
116
Abstract :
In an effort to enhance enterprise security, three standard management systems have been established as applications of the Deming cycle: the Information Security Management System (ISMS) in accordance with the ISO 27001 standard, the Business Continuity Management System (BCM) in accordance with the BS 25999 standard and the Information Technology Service Management System (ITSM) in accordance with the ISO 20000 standard. These three management systems have been developed to operate independent of one another, but are often used together within a given company. It can be shown that management systems modeled after the Deming cycle behave as bisimulations with dynamic feedback policies and can be expressed formally as control circuits within the Discrete Event Systems (DES) theory. In this article, we present an analytical description of the optimal structure through which the three management systems (ISMS, BCMS, and ITSM) should be linked in a company. We define a coupling parameter and, using an equation for the discrete control loop, show that ISMS and ITSM should ideally be strongly coupled, and ISMS and BCMS should be weakly coupled.
Keywords :
ISO standards; discrete event systems; information systems; security of data; BS 25999 standard; Deming cycle; ISO 20000 standard; ISO 27001 standard; bisimulations behavior; business continuity management system; coupling parameter; discrete control loop; discrete event systems theory; information security management system; information technology service management system; strongly coupled management system; weakly coupled management system; Actuators; Automata; Companies; ISO standards; Process control; Security; bisimulation; control loop; control systems engineering; coupled management systems; dynamic policies; strong/weak coupling;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Emerging Security Information Systems and Technologies (SECURWARE), 2010 Fourth International Conference on
Conference_Location :
Venice
Print_ISBN :
978-1-4244-7517-9
Electronic_ISBN :
978-0-7695-4095-5
Type :
conf
DOI :
10.1109/SECURWARE.2010.26
Filename :
5633657
Link To Document :
بازگشت