Practical Application of a Security Management Maturity Model for SMEs based on Predefined Schemas
نویسندگان
چکیده
For enterprises to be able to use information technologies and communications with guarantees, it is necessary to have an adequate security management system and tools which allow them to manage it. In small and medium-sized enterprises, the application of security standards has an additional problem, which is the fact that they do not have enough resources to carry out an appropriate management. This security management system must have highly reduced costs for its implementation and maintenance in small and medium-sized enterprises (from here on refered to as SMEs) to be feasible. In this paper we show the practical application of our proposal for a maturity model with which to manage the security in SMEs, centring upon the phase which determines the state of the enterprise and some of the mechanisms which allow the security level to be kept up to date without the need for continuous audits. This focus is continuously refined through its application to real cases, the results of which are shown in this paper.
منابع مشابه
Developing a Model and a Tool to Manage the Information Security in Small and Medium Enterprises
The maturity and security management systems are essential in order to guarantee the continuity and stability of the companies in the current market situation. However, this requires that enterprises know in every moment their security maturity level and to what extend their information security system must evolve. In small and medium-sized enterprises, the application of security standards has...
متن کاملMultidimensional Business to Business E-Commerce Maturity Application: Assessment on Its Practicality
In most countries, Small Medium Enterprise (SMEs) are known as main players in generating domestic-led investment and stimulate economic expansion. They are vital for economic growth and innovation, poverty reduction, local employment and development, and social cohesion. However, in the current digitally-connected trading economy, SMEs have face many new challenges that change the way SMEs bus...
متن کاملISMS Building for SMEs through the Reuse of Knowledge
The information society is increasingly more dependent upon Information Security Management Systems (ISMSs), and the availability of these systems has become crucial to the evolution of Small and Mediumsize Enterprises (SMEs). However, this type of companies requires ISMSs which have been adapted to their specific characteristics, and these systems must be optimized from the point of view of th...
متن کاملManaging Security and its Maturity in Small and Medium-sized Enterprises
Due to the growing dependence of information society on Information and Communication Technologies, the need to protect information is getting more and more important for enterprises. In this context, Information Security Management Systems (ISMSs), have arisen for supporting the processes and systems for effectively managing information security. The fact of having these systems available has ...
متن کاملPrivate Key based query on encrypted data
Nowadays, users of information systems have inclination to use a central server to decrease data transferring and maintenance costs. Since such a system is not so trustworthy, users' data usually upkeeps encrypted. However, encryption is not a nostrum for security problems and cannot guarantee the data security. In other words, there are some techniques that can endanger security of encrypted d...
متن کامل