Skip to main content

2017 | OriginalPaper | Buchkapitel

A System Design for the Measurement and Evaluation of the Communications Security Domain in ISO 27001:2013 Using an Ontology

verfasst von : Pongsak Sirisom, Janjira Payakpate, Winai Wongthai

Erschienen in: Information Science and Applications 2017

Verlag: Springer Singapore

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

This paper presents a system design using the design and linking semantic technology of ontologies by mapping the structure base and finding identical meanings of each text. The Wu and Palmer method and WordNet database were used for this purpose. The accuracy of the results of the concept are measured by using Recall, Precision, and F-Measure. Then, the proposed designed can be used to developed tools to qualify the security system for communications security domain under the standards of information security management for ISO 27001:2013. However, the cost of certification to organisations to meet international standards is considerable. Our intention was to demonstrate the ontology-based concept for organisations to be able to reduce their certification costs by waiving the requirement for an external consultant to evaluate their standards and policies.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
2.
Zurück zum Zitat Kanno, Y.: Information Security Measures Benchmark (ISM-Benchmark). IT Security Center, Information-Technology Promotion Agency, Japan (2009) Kanno, Y.: Information Security Measures Benchmark (ISM-Benchmark). IT Security Center, Information-Technology Promotion Agency, Japan (2009)
3.
Zurück zum Zitat Sharma, N.K., Dash, P.K.: Effectiveness of ISO 27001, as an information security management system: an analytical study of financial aspects. Far East J. Psychol. Bus. 9(3), 42–55 (2012) Sharma, N.K., Dash, P.K.: Effectiveness of ISO 27001, as an information security management system: an analytical study of financial aspects. Far East J. Psychol. Bus. 9(3), 42–55 (2012)
4.
Zurück zum Zitat Uschold, M., Gruninger, M.: Ontologies principles methods and applications. Knowl. Eng. Rev. 11(2), 93–155 (1996)CrossRef Uschold, M., Gruninger, M.: Ontologies principles methods and applications. Knowl. Eng. Rev. 11(2), 93–155 (1996)CrossRef
6.
Zurück zum Zitat Miller, G.A., Beckwith, R., Fellbaum, C., Gross, D., Miller, K.: Introduction to WordNet: an on-line lexical database. Int. J. Lexicogr. 3, 235–244 (1990)CrossRef Miller, G.A., Beckwith, R., Fellbaum, C., Gross, D., Miller, K.: Introduction to WordNet: an on-line lexical database. Int. J. Lexicogr. 3, 235–244 (1990)CrossRef
7.
Zurück zum Zitat Pérez, J., Arenas, M., Gutierrez, C.: Semantics and complexity of SPARQL. Universidad de Talca, Chile (2009) Pérez, J., Arenas, M., Gutierrez, C.: Semantics and complexity of SPARQL. Universidad de Talca, Chile (2009)
8.
Zurück zum Zitat Lovrić, Z.: Model of simplified implementation of PCI DSS by using ISO 27001 standard. In: Central European Conference on Information and Intelligent Systems, 19–21 September 2012 Lovrić, Z.: Model of simplified implementation of PCI DSS by using ISO 27001 standard. In: Central European Conference on Information and Intelligent Systems, 19–21 September 2012
9.
Zurück zum Zitat Shrivastava, A.K.: ISO27001 compliance via artificial neural network. In: 13th IEEE International Symposium on Pacific Rim Dependable Computing (2007) Shrivastava, A.K.: ISO27001 compliance via artificial neural network. In: 13th IEEE International Symposium on Pacific Rim Dependable Computing (2007)
10.
Zurück zum Zitat Fenz, S., Weippl, E.: Ontology based IT-security planning. In: Secure Business, Austria (2006) Fenz, S., Weippl, E.: Ontology based IT-security planning. In: Secure Business, Austria (2006)
11.
Zurück zum Zitat Fenz, S., Goluch, G., Ekelhart, A., Riedl, B., Weippl, E.: Information security fortification by ontological mapping of the ISO/IEC 27001 standard. In: 13th IEEE International Symposium on Pacific Rim Dependable Computing (2007) Fenz, S., Goluch, G., Ekelhart, A., Riedl, B., Weippl, E.: Information security fortification by ontological mapping of the ISO/IEC 27001 standard. In: 13th IEEE International Symposium on Pacific Rim Dependable Computing (2007)
12.
Zurück zum Zitat Fenz, S.: Ontology-based generation of IT-security metrics. In: SAC 2010, Sierre, Switzerland, 22–26 March 2010 Fenz, S.: Ontology-based generation of IT-security metrics. In: SAC 2010, Sierre, Switzerland, 22–26 March 2010
13.
Zurück zum Zitat Liu, X., Cao, L., Dai, W.: Overview of ontology mapping and approach. In: 2011 4th IEEE International Conference on Broadband Network and Multimedia Technology (IC-BNMT), pp. 592–595, 28–30 October 2011 Liu, X., Cao, L., Dai, W.: Overview of ontology mapping and approach. In: 2011 4th IEEE International Conference on Broadband Network and Multimedia Technology (IC-BNMT), pp. 592–595, 28–30 October 2011
14.
Zurück zum Zitat Wu, Z., Palmer, M.: Verb semantic and lexical selection. In: Proceeding of 32nd Annual Meeting of the Association for Computational Linguistics (ACL), Las Cruces, US, pp. 133–138 (1994) Wu, Z., Palmer, M.: Verb semantic and lexical selection. In: Proceeding of 32nd Annual Meeting of the Association for Computational Linguistics (ACL), Las Cruces, US, pp. 133–138 (1994)
15.
Zurück zum Zitat Corley, C., Mihalcea, R.: Measuring the semantic similarity of texts. Department of Computer Science, University of North Texas (2005) Corley, C., Mihalcea, R.: Measuring the semantic similarity of texts. Department of Computer Science, University of North Texas (2005)
16.
Zurück zum Zitat Fernando, S., Stevenson, M.: A semantic similarity approach to paraphrase detection. Department of Computer Science, University of Sheffield, Sheffield, UK (2008) Fernando, S., Stevenson, M.: A semantic similarity approach to paraphrase detection. Department of Computer Science, University of Sheffield, Sheffield, UK (2008)
Metadaten
Titel
A System Design for the Measurement and Evaluation of the Communications Security Domain in ISO 27001:2013 Using an Ontology
verfasst von
Pongsak Sirisom
Janjira Payakpate
Winai Wongthai
Copyright-Jahr
2017
Verlag
Springer Singapore
DOI
https://doi.org/10.1007/978-981-10-4154-9_30

Neuer Inhalt