Vis enkel innførsel

dc.contributor.authorAgrawal, Vivek
dc.date.accessioned2018-02-20T08:02:32Z
dc.date.available2018-02-20T08:02:32Z
dc.date.created2017-07-25T15:23:04Z
dc.date.issued2017
dc.identifier.isbn978-1-5090-6643-8
dc.identifier.urihttp://hdl.handle.net/11250/2485798
dc.description.abstractInformation Security Risk Management (ISRM) process involves several activities to conduct a risk management (RM) task in an organization. ISRM activities require access to various information related to the organization. An organization often needs to share information related to an ISRM process with the stakeholders involved in the activity. Therefore, it is important to manage the information which is critical to the operations of the organization. The presence of an information classification scheme can enable the proper handling of the information involved in the RM task. We selected ISO/IEC27005:2011 risk management standard to assess various information generated during the process of applying this standard in an organization. The purpose of this study is to propose a framework to show various information objects involved in ISO27005 risk management standard and classify the information based on the guideline provided by UNINETT scheme. A case scenario of a health clinic is developed to identify ISRM related information objects using the proposed framework and classify the information using UNINETT scheme.nb_NO
dc.language.isoengnb_NO
dc.publisherInstitute of Electrical and Electronics Engineers (IEEE)nb_NO
dc.relation.ispartof2017 IEEE 4th International Conference on Cyber Security and Cloud Computing (CSCloud)
dc.relation.urihttp://ieeexplore.ieee.org/document/7987208/
dc.titleA Framework for the Information Classification in ISO 27005 Standardnb_NO
dc.typeChapternb_NO
dc.description.versionacceptedVersionnb_NO
dc.source.pagenumber264-269nb_NO
dc.identifier.doi10.1109/CSCloud.2017.13
dc.identifier.cristin1483068
dc.description.localcode© 2017 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.nb_NO
cristin.unitcode194,18,21,90
cristin.unitnameAIMT Avdelingsadministrasjon
cristin.ispublishedtrue
cristin.fulltextoriginal
cristin.qualitycode1


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel