首页    期刊浏览 2024年09月21日 星期六
登录注册

文章基本信息

  • 标题:IT Security Management Implementation Model in Iranian Bank Industry
  • 本地全文:下载
  • 作者:Vanaki, Mona ; Taghva, Mohammad Reza ; Taghavifard, Mohammad Taghi
  • 期刊名称:Journal of Information Technology Management
  • 印刷版ISSN:2008-5893
  • 出版年度:2017
  • 卷号:9
  • 期号:2
  • 页码:379-404
  • DOI:10.22059/jitm.2017.61097
  • 摘要:According to the complexity and differences between Iranian banks and other developed countries the appropriate actions to implement effective security management of information technology have not been taken. The aim of this study was to create a powerful model by selecting the appropriate security controls to protect information assets in the bank. In this model, at first the principle set fort in ISO standard 27001, was extracted and then by further studies derived from best practices carried out in the world on the related subject from 2008 to 2016 using a qualitative descriptive method), points comply with information security management in the banking industry were added to it. With the study of Iranian banks in dealing with IT security management system and with help of action research tools, provisions which prevent the actual implementation of this standard was removed and finally a conceptual model with operating instructions and considering all the principles of information security management standard, as well as banking institutions focusing on the characteristics of Iran was proposed.
  • 关键词:Asset;Banking;Information security management system certification;ISO 27001 standard
国家哲学社会科学文献中心版权所有