Security Documentation

Lam-For KWOK, Peggy P K FUNG, Dennis LONGLEY

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

Abstract

Information Security Management Standards and Code of Practice provide guidance on good practice for security officers. However there is still a significant gap between the security officer's real world environment and the advice provided by information security professionals and consultants. This paper suggests that a uniform approach to security documentation may provide a first step in bridging that gap, and discusses a proposed structure for such documentation. It is clear from this discussion, however, that a first attempt at security documentation reveals a more fundamental problem, the lack of a working security model. Having documented the local security scenario, the security officer requires some means to extract security relevant information, e.g. to advise management on the current state of organizational security and to recommend security priorities. This paper concludes with a discussion on such a security model. © IFIP International Federation for Information Processing 2001
Original languageEnglish
Title of host publicationAdvances in Information Security Management & Small Systems Security
Subtitle of host publicationIFIP TC11 WG11.1/WG11.2 Eighth Annual Working Conference on Information Security Management & Small Systems Security September 27–28, 2001, Las Vegas, Nevada, USA
EditorsJan H. P. Eloff, Les Labuschagne, Rossouw Solms
Place of PublicationNew York, NY
PublisherSpringer 
Pages127-139
ISBN (Electronic)978-0-306-47007-3
ISBN (Print)9780792375067, 978-1-4757-7496-2
DOIs
Publication statusPublished - 2002
EventIFIP TC11 WG11.1/WG11.2 8th Annual Working Conference on Information Security Management and Small Systems Security - Las Vegas, NV, United States
Duration: 27 Sept 200128 Sept 2001

Publication series

NameIFIP Advances in Information and Communication Technology
Volume72
ISSN (Print)1868-4238
ISSN (Electronic)1868-422X

Conference

ConferenceIFIP TC11 WG11.1/WG11.2 8th Annual Working Conference on Information Security Management and Small Systems Security
PlaceUnited States
CityLas Vegas, NV
Period27/09/0128/09/01

Research Keywords

  • Countermeasures
  • Risk analysis
  • Security documentation
  • Security model
  • Security standards

Fingerprint

Dive into the research topics of 'Security Documentation'. Together they form a unique fingerprint.

Cite this