標題: | A study on information security management system evaluation - assets, threat and vulnerability |
作者: | Farn, KJ Lin, SK Fung, ARW 資訊管理與財務金融系 註:原資管所+財金所 Department of Information Management and Finance |
關鍵字: | certification;evaluation;framework;Information Security Management System;National Information Assurance Certification and;accreditation process |
公開日期: | 1-十月-2004 |
摘要: | The security of information system is like a chain. Its strength is affected by the weakest knot. Since we can achieve 100% Information Security Management System (ISMS) security, we must cautiously fulfill the certification and accreditation of information security. In this paper, we analyzed, studied the evaluation knowledge and skills required for auditing the certification procedures for the three aspects of ISMS-asset, threat, and vulnerability. (C) 2004 Elsevier B.V. All rights reserved. |
URI: | http://dx.doi.org/10.1016/j.csi.2004.03.012 http://hdl.handle.net/11536/26338 |
ISSN: | 0920-5489 |
DOI: | 10.1016/j.csi.2004.03.012 |
期刊: | COMPUTER STANDARDS & INTERFACES |
Volume: | 26 |
Issue: | 6 |
起始頁: | 501 |
結束頁: | 513 |
顯示於類別: | 期刊論文 |