Common defects in information security management system of Korean companies

  • Kwon, Sungho
  • Jang, Sangsoo
  • Lee, Jaeill
  • Kim, Sangkyun
Citations

WEB OF SCIENCE

7
Citations

SCOPUS

11

초록

To reduce the possible trials and errors while promoting the establishment and certification of the information security management system (ISMS) by enterprises is the purpose of this paper. To satisfy this purpose, this study presents the defects by item found during the certification process of the ISMS of a number of enterprises by government certification agency in Korea. As a result, by analyzing the derived defects, this paper has outlined the issues to be attended to among enterprises at each stage of the establishment of the ISMS. Furthermore, this study presents a reference model for conducting a self assessment, so that companies may be able to self verify the completeness of their establishment of the ISMS. The case study is also provided to prove the practical value of this study. 2007 Elsevier Inc. All rights reserved.

키워드

information security management systemreference modelself assessment
제목
Common defects in information security management system of Korean companies
저자
Kwon, SunghoJang, SangsooLee, JaeillKim, Sangkyun
DOI
10.1016/j.jss.2007.01.015
발행일
2007-10
유형
Article
저널명
Journal of Systems and Software
80
10
페이지
1631 ~ 1638