Building a Viable Information Security Management System

Sabine Goldes,Ralf Schneider,Christian M. Schweda,Jawed Zamani
DOI: https://doi.org/10.1109/cybconf.2017.7985763
2017-06-01
Abstract:Information Security is a topic of increasing importance for organizations today. The triad of professionalization and industrialization of cyber-crime, globalization and digitalization of business models, and increasing regulatory focus on data protection exerts pressure on organizations and enterprises to implement sophisticated Information Security Management Systems (ISMS). Best-practices for implementing such systems are given by multiple de-facto standards, whereas blueprints for ISMS are relatively scarce. In this paper we discuss design requirements for a modern Information Security Management System, derive a blueprint for such a system based on the viable system approach, and exemplify constituents of the blueprint from the environment of an insurance enterprise.
What problem does this paper attempt to address?