Trudy SPIIRAN
RUS  ENG    JOURNALS   PEOPLE   ORGANISATIONS   CONFERENCES   SEMINARS   VIDEO LIBRARY   PACKAGE AMSBIB  
General information
Latest issue
Archive

Search papers
Search references

RSS
Latest issue
Current issues
Archive issues
What is RSS



Informatics and Automation:
Year:
Volume:
Issue:
Page:
Find






Personal entry:
Login:
Password:
Save password
Enter
Forgotten password?
Register


Trudy SPIIRAN, 2015, Issue 40, Pages 33–44
DOI: https://doi.org/10.15622/sp.40.3
(Mi trspy801)
 

This article is cited in 2 scientific papers (total in 2 papers)

Practical Assessment of the ISMS Effectiveness in Accordance with the Requirements of the Various Standardization Systems both ISO 27001 and STO Gazprom

I. I. Livshitza, A. V. Poleshukb

a LLC “Gasinformservice”
b JSC "IT-System Academia"
Full-text PDF (868 kB) Citations (2)
Abstract: This issue briefly covers the need of numerical evaluation for Information Security Management Systems (ISMS) effectiveness in accordance with the requirements of two or more different standardization systems, such as ISO / IEC 27001 series of standards and Information Security Providing System STO Gazprom series 4.2 (ISPS). This problem is important to minimize the violation of IT-security risks and ensure the information processes stability in the information systems. This issue describes methodological difficulties in reconciling the requirements of different Standardization systems both ISO / IEC and ISPS that must be considered when assessing the ISMS effectiveness. The formulas have been proposed to solve the problem for calculating the ISMS effectiveness and discussed practical examples (cases), explaining the calculation for specific situations. These results can be used to create models and methods to provide the ISMS audits and monitoring IT-security facilities both ISMS and / or ISPS Gazprom.
Keywords: Information Security (IT-Security); Information Security Management System (ISMS); Information Security Providing System (ISPS); Effectiveness; Metrics; Object of Protection (ObP); Audit; Controls; PDCA Cycle; Risk Management.
Bibliographic databases:
Document Type: Article
UDC: 004.94
Language: Russian


Citation: I. I. Livshitz, A. V. Poleshuk, “Practical Assessment of the ISMS Effectiveness in Accordance with the Requirements of the Various Standardization Systems both ISO 27001 and STO Gazprom”, Tr. SPIIRAN, 40 (2015), 33–44
Linking options:
  • https://www.mathnet.ru/eng/trspy801
  • https://www.mathnet.ru/eng/trspy/v40/p33
  • This publication is cited in the following 2 articles:
    Citing articles in Google Scholar: Russian citations, English citations
    Related articles in Google Scholar: Russian articles, English articles
    Informatics and Automation
    Statistics & downloads:
    Abstract page:308
    Full-text PDF :190
     
      Contact us:
     Terms of Use  Registration to the website  Logotypes © Steklov Mathematical Institute RAS, 2024