Title :
A Proposed Preventive Information Security System
Author :
Anwar, M.M. ; Zafar, M.F. ; Ahmed, Z.
Author_Institution :
ICCC, Islamabad
Abstract :
Managing computer and network security programs has become an increasingly difficult and challenging job. Dramatic advances in computing and communications technology during the past few years have redirected the focus of data processing from the computing center to the terminals in individual offices and homes. The result is that managers must now monitor security on a more widely dispersed level. These changes are continuing to accelerate, making the security manager´s job increasingly difficult. In this paper a better solution for Information Security management has been proposed by designing PrISM (Preventive Information Security Management). PrISM aims to develop and deploy an indigenous Information Security Management System (ISMS) with intrusion prevention capabilities. The objective is to develop an ISMS with appropriate security assurance controls and risk handling processes. This will provide best protection of critical assets against information warfare attacks. The task has been planned by performing reverse engineering of Open Source Security Information Management (OSSIM) system. A detailed discussion on OSSIM and commercially available software Event Horizon has also been presented.
Keywords :
computer network management; telecommunication security; OSSIM; PrISM; Preventive Information Security Management; communications technology; data processing; indigenous information security management system; information warfare attacks; open source security information management; preventive information security system; reverse engineering; risk handling processes; Communication system security; Communications technology; Computer network management; Computer networks; Computer security; Data processing; Data security; Home computing; Information management; Information security; Information Security Management System; computer security; intrusion detection; network security;
Conference_Titel :
Electrical Engineering, 2007. ICEE '07. International Conference on
Conference_Location :
Lahore
Print_ISBN :
1-4244-0893-8
Electronic_ISBN :
1-4244-0893-8
DOI :
10.1109/ICEE.2007.4287288