Application of models in information security management

Danijel Milicevic, Matthias Goeken · 2011

The impact of information technology on business operations is widely recognized and its role in the emergence of new business models is well-known. In order to leverage the benefits of IT-supported business processes the security of the underlying information systems must be managed. Various socalled best-practice models and information security standards have positioned themselves as generic solutions for a broad range of risks. In this paper we inspect the metamodel of the information security standard ISO 27001 and describe its application for a set of generalized phases in information security management. We conclude with a demonstration of its practicality by providing an example of how such a metamodel can be applied, before discussing potential future research.

Read the paper · More papers on PaperTik