Development of the Information Security Methodology for Defense Organization
2013
As Cyber threats are rising, the scope of information Security (IS) is extending from technical protection of a single information system to organizational comprehensive IS capability. The ministry of National Defense (MND) has established the IS evaluation for defense organization in `the Directive for Defense Informatization Affairs.` However, no information about an evaluation method, process and organization is provided. We surveyed information security management system (ISMS) and related best practices in public sector and other countries, and analysed the military information security affairs. Thus, this paper recommends the IS evaluation method and process. The trial IS evaluation is in progress this year and the MND will expand this IS evaluation to the entire organization.
Keywords:
- Business
- EBIOS
- MIL-STD-188
- Environmental resource management
- Security information and event management
- Information security management
- Certified Information Security Manager
- Information security audit
- Host Based Security System
- Certified Information Systems Security Professional
- Information security standards
- Information security
- Process management
- Information security management system
- Public relations
- Correction
- Source
- Cite
- Save
- Machine Reading By IdeaReader
3
References
0
Citations
NaN
KQI