INFORMATION SECURITY MATURITY ASSESSMENT MODEL

Evandro Alencar Rigon, Carla Merkle Westphall
DOI: https://doi.org/10.5329/RESI.2013.1201003

Abstract

Business processes are supported by information technologies, although many processes and information systems were not designed to be secure. The lack of a security evaluation method might expose organizations to several risky situations. This work presents an information security maturity management process which uses a measurement method and a set of controls which treat information security on a comprehensive way. The results indicate that the method is efficient for evaluating the current state of information security, to support information security management, risks identification, the improvement of business processes and internal control processes.

Keywords

segurança; maturidade; riscos


Compartilhe