The Experts below are selected from a list of 5262 Experts worldwide ranked by ideXlab platform
Andrzej Bialas - One of the best experts on this subject based on the ideXlab platform.
-
SAFECOMP - Development of an integrated, risk-based platform for Information and e-services Security
Lecture Notes in Computer Science, 2006Co-Authors: Andrzej BialasAbstract:The paper presents a risk-based integrated platform for the Information and e-services Security management related to the Information Security Managements System (ISMS) concept. The current state of the work is shown, including the UML-based methodology, and the incrementally developed computer-aided tool prototype. The assumptions of the integrated platform can be specified on the basis of sampled experiences from the first deployment and case studies, an analysis of standards, legal requirements and technology, and a study of the needs and requirements of various organizations. It is assumed that the common and enhanced assets inventory will integrate Information Security, business continuity and IT services management processes. The paper concludes the current, initial state of the work and defines its further directions.
-
Development of an Integrated, Risk-Based Platform for Information and E-Services Security
Lecture Notes in Computer Science, 2006Co-Authors: Andrzej BialasAbstract:The paper presents a risk-based integrated platform for the Information and e-services Security management related to the Information Security Managements System (ISMS) concept. The current state of the work is shown, including the UML-based methodology, and the incrementally developed computer-aided tool prototype. The assumptions of the integrated platform can be specified on the basis of sampled experiences from the first deployment and case studies, an analysis of standards, legal requirements and technology, and a study of the needs and requirements of various organizations. It is assumed that the common and enhanced assets inventory will integrate Information Security, business continuity and IT services management processes. The paper concludes the current, initial state of the work and defines its further directions.
Jyn Schultzemelling - One of the best experts on this subject based on the ideXlab platform.
-
it sicherheit in der anwaltlichen beratung rechtliche praktische und wirtschaftliche aspekte eines effektiven Information Security Managements
Computer Und Recht: Forum für die Praxis des Rechts der Datenverargeitung Information und Automation, 2005Co-Authors: Jyn SchultzemellingAbstract:Vue d'ensemble sur la securite informatique: menaces internes et externes, normes, certification. Responsabilite legales. Aspects ecomomiques. Etapes de la mise en oeuvre d'un plan de securite informatique.
Yi-fen Chen - One of the best experts on this subject based on the ideXlab platform.
-
Evaluating the ISO/IEC 27001 with Experts' Knowledge for Taiwanese Medical Center
Journal of Convergence Information Technology, 2011Co-Authors: Chi-chang Chang, Pei-ran Sun, Kuo-hsiung Liao, Yi-fen ChenAbstract:Information Security is a management problem, not a technology one. Experience indicates that technology cannot provide all the answers to the problems posed by people in the context of Information Security management (ISM). Since the improvements of Information Security Managements are crucial for all healthcare organizations. The Information they possess is very personal, while the trust between the patient and the hospital is one basic factor for quality care. Therefore hospital Information Security and privacy are major issues that cannot be ignored. For the Information Security management, ISO/IEC 27001 is the most important standards and it plays an important role while the organizations are considering strengthening their Security management. This research uses case study methods to observe and understand the Information Security management system of our research subject. We used the nominal group technique (NGT) that was developed on the basis of “ISO/IEC 27001”to develop models that could verify their Information Security management systems. The primary data was collected in the NGT and uses a structured group process to elicit and prioritize answers to a carefully articulated question. The chosen expert panel consists of the following interest groups. Based on the result of this study, we found that NGT represents a workable research tool in hospital Information Security management to capture multifaceted and enriched view about risk factors selecting. Finally, it not only can realize the more accurate potential risk incident by utilize the ISO/IEC 27001, but also achieved the objective for self-assessed management of hospital Information Security.
Chi-chang Chang - One of the best experts on this subject based on the ideXlab platform.
-
Evaluating the ISO/IEC 27001 with Experts' Knowledge for Taiwanese Medical Center
Journal of Convergence Information Technology, 2011Co-Authors: Chi-chang Chang, Pei-ran Sun, Kuo-hsiung Liao, Yi-fen ChenAbstract:Information Security is a management problem, not a technology one. Experience indicates that technology cannot provide all the answers to the problems posed by people in the context of Information Security management (ISM). Since the improvements of Information Security Managements are crucial for all healthcare organizations. The Information they possess is very personal, while the trust between the patient and the hospital is one basic factor for quality care. Therefore hospital Information Security and privacy are major issues that cannot be ignored. For the Information Security management, ISO/IEC 27001 is the most important standards and it plays an important role while the organizations are considering strengthening their Security management. This research uses case study methods to observe and understand the Information Security management system of our research subject. We used the nominal group technique (NGT) that was developed on the basis of “ISO/IEC 27001”to develop models that could verify their Information Security management systems. The primary data was collected in the NGT and uses a structured group process to elicit and prioritize answers to a carefully articulated question. The chosen expert panel consists of the following interest groups. Based on the result of this study, we found that NGT represents a workable research tool in hospital Information Security management to capture multifaceted and enriched view about risk factors selecting. Finally, it not only can realize the more accurate potential risk incident by utilize the ISO/IEC 27001, but also achieved the objective for self-assessed management of hospital Information Security.
Pei-ran Sun - One of the best experts on this subject based on the ideXlab platform.
-
Evaluating the ISO/IEC 27001 with Experts' Knowledge for Taiwanese Medical Center
Journal of Convergence Information Technology, 2011Co-Authors: Chi-chang Chang, Pei-ran Sun, Kuo-hsiung Liao, Yi-fen ChenAbstract:Information Security is a management problem, not a technology one. Experience indicates that technology cannot provide all the answers to the problems posed by people in the context of Information Security management (ISM). Since the improvements of Information Security Managements are crucial for all healthcare organizations. The Information they possess is very personal, while the trust between the patient and the hospital is one basic factor for quality care. Therefore hospital Information Security and privacy are major issues that cannot be ignored. For the Information Security management, ISO/IEC 27001 is the most important standards and it plays an important role while the organizations are considering strengthening their Security management. This research uses case study methods to observe and understand the Information Security management system of our research subject. We used the nominal group technique (NGT) that was developed on the basis of “ISO/IEC 27001”to develop models that could verify their Information Security management systems. The primary data was collected in the NGT and uses a structured group process to elicit and prioritize answers to a carefully articulated question. The chosen expert panel consists of the following interest groups. Based on the result of this study, we found that NGT represents a workable research tool in hospital Information Security management to capture multifaceted and enriched view about risk factors selecting. Finally, it not only can realize the more accurate potential risk incident by utilize the ISO/IEC 27001, but also achieved the objective for self-assessed management of hospital Information Security.