Corporate Security Compliance in a Heterogeneous Environment
Florence Yip, Alfred Ka Yiu Wong, PRADEEP KUMAR RAY, N. Paramesh · 2006
Organizations often have to audit and assess their information system security as a corporate compliance process based on a range of standards. The growing number of security standards such as CobiT, ISO17799 and BSI raises the potential interoperability problem in a heterogeneous environment. Often different standards are needed to satisfy different regional regulatory and obligatory requirements. In this paper, we present an ontology based approach to deal with the interoperability problem.