DocumentCode :
2194897
Title :
Toward a Target Function of an Information Security Management System
Author :
Boehmer, Wolfgang
Author_Institution :
Tech. Univ. Darmstadt, Darmstadt, Germany
fYear :
2010
fDate :
June 29 2010-July 1 2010
Firstpage :
809
Lastpage :
816
Abstract :
The limits of traditional (static) policies are wellknown in many areas of computer science and information security, and are extensively discussed in the literature. Although some flexibility has been achieved with the introduction of dynamic policies, these efforts have only addressed a fraction of the requirements necessary to secure today\´s enterprises. Currently, no feedback mechanisms are in place to evaluate the effectiveness or economic impacts of static or dynamic policy implementation. Here, we address the requirement for feedback and present a policy for the next generation. This is a policy that includes a dynamic feedback response to the effectiveness of changes. The structure of this new type of policy, called a "management system", is borrowed from discrete event system (DES) theory and functions as a control loop. A management system consists of four elements (control system, sensor, controller, and actuator) that are involved in a control law. Two types of management system can be defined. A simple management system (1st order management system) responds to and regulates only perturbations. An advanced management system (2nd order management system) has an overarching target function that influences the controller. This target function is usually economically oriented. Finally, we compare our new type of policy with two management systems that follows the Plan-Do-Check-Act (PDCA cycle) model. We investigate the two PDCA cycle standards ISO/IEC 27001 (Information Security Management System, ISMS) and BS 25999 (Business Continuity Management System, BCMS). We also show that the new type of policy can be applied to management systems based on a PDCA cycle.
Keywords :
business continuity; discrete event systems; feedback; information management; security of data; BCMS; ISMS; ISO-IEC 27001; PDCA cycle standards; advanced management system; business continuity management system; computer science; discrete event system; dynamic policy implementation; information security management system; plan-do-check-act; target function; Actuators; Automata; Companies; ISO standards; Process control; 1$^textrm{st}$ order management system; 2$^textrm{nd}$ order management system; Static/dynamic policies; balance system; control loop;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer and Information Technology (CIT), 2010 IEEE 10th International Conference on
Conference_Location :
Bradford
Print_ISBN :
978-1-4244-7547-6
Type :
conf
DOI :
10.1109/CIT.2010.154
Filename :
5578082
Link To Document :
بازگشت