论文标题
使用成熟度对安全学术信息系统的绩效衡量
Performance Measurement of Security Academic Information System using Maturity Level
论文作者
论文摘要
这项研究旨在基于ISO/IEC 27002:2013的预期成熟度,为学术信息系统中的信息安全提供了建议,以改善信息安全管理。通过使用定性描述性方法,使用三角调节技术的数据收集和验证技术是访谈,观察和文档。通过使用GAP分析分析数据,并测量确定的成熟度15的目标控制和45个散布在5个条款中的安全控制,结果发现,学术信息系统成熟度在2级的成熟水平的性能。即当前的成熟度低于预期成熟度,因此需要将其提高到预期水平。
This study aims to information security in academic information systems to provide recommendations for improvements in information security management by the expected maturity level based on ISO/IEC 27002:2013. By using a qualitative descriptive approach, data collection and validation techniques with triangulation techniques are interviews, observation, and documentation. The data were analyzed by using gap analysis and to measure the maturity level determined 15 objective control and 45 security controls scattered in 5 clauses, the result of the research found that the performance of academic information system maturity level at level 2. That is, the current level of maturity is below the expected maturity level, so it needs to be increased to the expected level.