loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
First International Conference on Availability, Reliability and Security (ARES'06)
Practical Approach of a Secure Management System based on ISO/IEC 17799
Vienna, Austria
April 20-April 22
ISBN: 0-7695-2567-9
Lu?s Enrique Sanchez, SICAMAN NT., Spain
Daniel Villafranca, SICAMAN NT., Spain
Eduardo Fernandez-Medina, University of Castilla-La Mancha, Spain
Mario Piattini, University of Castilla-La Mancha, Spain

For enterprises to be able to properly use information and communications technologies, it is necessary to have guides, metrics and tools that allow us to always know the level of our security and the points in which we are not covering it. In small and medium-size enterprises, the application of security standards has an additional problem, that is, the fact that they do not have enough resources to perform an appropriate management. In this article we will analyze some of the existing maturity models and we will compare them to the maturity model we are applying in practice. Finally we will introduce a first approach to a scoreboard which is being developed as part of a security management tool for IT systems.

This approach is being directly applied to real cases and it is obtaining a constant improvement in its application.

Citation:
Lu?s Enrique Sanchez, Daniel Villafranca, Eduardo Fernandez-Medina, Mario Piattini, "Practical Approach of a Secure Management System based on ISO/IEC 17799," ares, pp.585-592, First International Conference on Availability, Reliability and Security (ARES'06), 2006
Usage of this product signifies your acceptance of the Terms of Use.