Addressing Information Security Risks by Adopting Standards

Volume: 2 Number: 2 June 28, 2013
  • Walid Al-ahmad
  • Bassil Mohammad
EN TR

Addressing Information Security Risks by Adopting Standards

Abstract

Modern society depends on information technology in nearly every facet of human activity including, finance, transportation, education, government, and defense. Organizations are exposed to various kinds of risks, including information technology risks. Several standards, best practices, and frameworks have been created to help organizations manage these risks. The purpose of this research work is to highlight the challenges facing enterprises in their efforts to properly manage information security risks when adopting international standards and frameworks. To assist in selecting the best framework to use in risk management, the article presents an overview of the most popular and widely used standards and identifies selection criteria. It suggests an approach to proper implementation as well. A set of recommendations is put forward with further research opportunities on the subject.

Keywords

References

  1. Symantec, “Symantec Global Internet Security Threat Report Trends for 2008”, Symantec’s Publications, Vol. XIV, 2009, pp. 10.
  2. www.gocsi.com, “Computer Crime and Security Survey”, accessed January 2012.
  3. B., Blakley, E., McDermott, and D., Geer, “Information Security is Information Risk Management”, ACM Digital Library, 2002.
  4. E., Humphreys, “Information security management standards: management”, Information Security Technical Report, Vol. 13, No. 4, 2008. governance and risk [5] H., Susanto, M., Almunawar, and Y. Tuan, “Information Security Management System Standards: A Comparative Study of the Big Five”, International Journal of Electrical & Computer Sciences, Vol. 11, No. 5, 2011.
  5. Y., Barlette and V., Fomin, The Adoption of Information Security Management Standards: A Literature Review, IGI Global, 2009.
  6. S., Schlarman, “Selecting an IT Control Framework”, EDPACS, Vol. 35, No. 2, 2007.
  7. , J., Sipiorand and B., Ward, “A Framework for Information Security Management Based on Guiding Standards”, Issues in Informing Science and Information Technology, Vol. 5, 2008.
  8. A., Tsohou, S., Kokolakis, C., Lambrinoudakis, and S., Gritzalis, "A security standards' framework to facilitate best practices' awareness and conformity", Information Management & Computer Security, Vol. 18, No. 5, 2010, pp.350 – 365.

Details

Primary Language

English

Subjects

-

Journal Section

-

Authors

Walid Al-ahmad This is me

Bassil Mohammad This is me

Publication Date

June 28, 2013

Submission Date

January 30, 2016

Acceptance Date

-

Published in Issue

Year 2013 Volume: 2 Number: 2

APA
Al-ahmad, W., & Mohammad, B. (2013). Addressing Information Security Risks by Adopting Standards. International Journal of Information Security Science, 2(2), 28-43. https://izlik.org/JA36MX38XG
AMA
1.Al-ahmad W, Mohammad B. Addressing Information Security Risks by Adopting Standards. IJISS. 2013;2(2):28-43. https://izlik.org/JA36MX38XG
Chicago
Al-ahmad, Walid, and Bassil Mohammad. 2013. “Addressing Information Security Risks by Adopting Standards”. International Journal of Information Security Science 2 (2): 28-43. https://izlik.org/JA36MX38XG.
EndNote
Al-ahmad W, Mohammad B (June 1, 2013) Addressing Information Security Risks by Adopting Standards. International Journal of Information Security Science 2 2 28–43.
IEEE
[1]W. Al-ahmad and B. Mohammad, “Addressing Information Security Risks by Adopting Standards”, IJISS, vol. 2, no. 2, pp. 28–43, June 2013, [Online]. Available: https://izlik.org/JA36MX38XG
ISNAD
Al-ahmad, Walid - Mohammad, Bassil. “Addressing Information Security Risks by Adopting Standards”. International Journal of Information Security Science 2/2 (June 1, 2013): 28-43. https://izlik.org/JA36MX38XG.
JAMA
1.Al-ahmad W, Mohammad B. Addressing Information Security Risks by Adopting Standards. IJISS. 2013;2:28–43.
MLA
Al-ahmad, Walid, and Bassil Mohammad. “Addressing Information Security Risks by Adopting Standards”. International Journal of Information Security Science, vol. 2, no. 2, June 2013, pp. 28-43, https://izlik.org/JA36MX38XG.
Vancouver
1.Walid Al-ahmad, Bassil Mohammad. Addressing Information Security Risks by Adopting Standards. IJISS [Internet]. 2013 Jun. 1;2(2):28-43. Available from: https://izlik.org/JA36MX38XG