- International Journal of Information Security Science
- Volume:2 Issue:2
- Addressing Information Security Risks by Adopting Standards
Addressing Information Security Risks by Adopting Standards
Authors : Walid ALAHMAD, Bassil MOHAMMAD
Pages : 28-43
View : 48 | Download : 6
Publication Date : 2013-06-28
Article Type : Research Paper
Abstract :Modern society depends on information technology in nearly every facet of human activity including, finance, transportation, education, government, and defense. Organizations are exposed to various kinds of risks, including information technology risks. Several standards, best practices, and frameworks have been created to help organizations manage these risks. The purpose of this research work is to highlight the challenges facing enterprises in their efforts to properly manage information security risks when adopting international standards and frameworks. To assist in selecting the best framework to use in risk management, the article presents an overview of the most popular and widely used standards and identifies selection criteria. It suggests an approach to proper implementation as well. A set of recommendations is put forward with further research opportunities on the subject.Keywords : Information security, risk management, security frameworks, security standards, security management
ORIGINAL ARTICLE URL
