Has your organization compliance with ISMS? A case study in an Iranian Bank
نویسنده
چکیده
Purpose – The purpose of this study is proposing a model to determine the gaps between security standards requirements and the reality of implementation ISMS. Design/methodology/approach – The research approach analyzes the various industry standards relevant to information security and responses gained from interviewing with 45 individuals of IT professionals and information security experts (who are chosen with targeted sampling) in order to develop a model comprising factors and subfactors which assesses compliance with ISMS (Information Security Management System) in organizations. For hypothesis test, binomial test and for ranking of factors and subfactors, Friedman test was done. This model tested in an iranian bank and the degree of compliance with ISMS calculated. Findings – The case study proposes a novel model based on the standards and experience of the IT professionals and information security experts, comprising factors and subfactors which assesses the degree of readiness of an organization for implementing ISMS or the degree of compliance with this system. Originality/value –Studies show Sometimes Implementing ISMS projects regarding government rules in organizations compliance with one of the existing ISMS standards are unsucceessful in achiving predifined security goals and 1 . Master of IT management, Department of Management, Allame Tabatabaei University, Iran Email: [email protected]
منابع مشابه
Analyzing the Interaction between the Central Bank and the Plan and Budget Organization (A Case Study of Iran Using Game Theory)
The central bank is working to reform the structure of the banking system to bring the banking network in line with world standards. The banking network should strive to adapt itself to the modern world in terms of technology, procedures, and operations. The main prerequisite for this is central bank independence and structural reform of the country's budget. In the current situation, the Centr...
متن کاملIntegrated Solution Modeling Software: A New Paradigm on Information Security Review
Actually Information security becomes a very important part for the organization’s intangible assets, so level of confidence and stakeholder trusted are performance indicator as successes organization. Since information security has a very important role in supporting the activities of the organization, we need a standard or benchmark which regulates governance over information security. The ma...
متن کاملIntegrated Solution Modeling Software: A New Paradigm on Information Security Review and Assessment
Actually Information security becomes a very important part for the organization’s intangible assets, so level of confidence and stakeholder trusted are performance indicator as successes organization. Since information security has a very important role in supporting the activities of the organization, we need a standard or benchmark which regulates governance over information security. The ma...
متن کاملIdentification and evaluation of factors affecting the adoption of e-banking in the customers of country's banking system (Case Study: Post Bank)
Today's world has been built on the basis of competition and uncertainty, thus the role of facilitators, such as technology and information technology is undeniable. In this research developed Technology Acceptance Model to identify and prioritizing the factors affecting was used on formation of decision and behavior of customers in adoption of Internet banking of Post Bank. The statistical pop...
متن کاملDerivation of Optimal Central Bank Transparency for Minimizing the Output Volatility: The Case Study of Organization of Islamic Cooperation
This paper aims to optimize the Central Bank transparency level which corresponds to the minimum of output volatility in 28 states of the Organization of Islamic Cooperation (due to the maximum data availability) during the period 2003-2014. For this purpose, the Dincer-Eichengreen index is used, which includes five aspects covering political, economic, procedural, policy, and operational trans...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- CoRR
دوره abs/1303.0468 شماره
صفحات -
تاریخ انتشار 2013