Open Information Security Management Maturity Model: Difference between revisions

Content deleted Content added
Created page with ''''The Open Group Architecture Framework''' ('''O-ISM3''') is a Information Security Management Framework that provides an approach for designing, planning, impl...'
 
m Importing Wikidata short description: "Framework for managing information security"
 
(39 intermediate revisions by 17 users not shown)
Line 1:
{{Short description|Framework for managing information security}}
'''The Open Group Architecture Framework''' ('''O-ISM3''') is a Information Security Management Framework that provides an approach for designing, planning, implementing, and governing information security management systems.
The '''[[The Open Group|Open Group]] Information Security Management Maturity Model''' ('''O-ISM3''') is a [[maturity model]] for managing [[information security]]. It aims to ensure that security processes in any organization are implemented so as to operate at a level consistent with that organization’s business requirements. O-ISM3 defines a comprehensive but manageable number of information security processes sufficient for the needs of most organizations, with the relevant security control(s) being identified within each process as an essential subset of that process. <ref>O-ISM3 v2.0 2018 p6</ref>
 
== History ==
The original motivation behind O-ISM3 development was to narrow the gap between theory and practice for information security management systems, and the trigger was the idea of linking security management and maturity models. O-ISM3 strove to keep clear of the pitfalls pointed out in the article “Designing Secure Information Systems and software: Critical Evaluation of the Existing Approaches and a New Paradigm,” by Mikko Siponen. The project looked at CMMI, ISO9001, COBIT, ITIL, ISO27001, and other standards, and found some potential for improvement in several fields, such as linking security to business needs, using a process based approach, providing some additional details (who, what, why) for implementation and suggesting specific metrics, while preserving compatibility with current IT and security management standards.
The original motivation behind O-ISM3 development was to narrow the gap between theory and practice for information security management systems, and the trigger was the idea of linking security management and maturity models. O-ISM3 strove to keep clear of a number of pitfalls with previous approaches.<ref name="mikko">Siponen, Mikko (2002-08-24). Designing Secure Information Systems and Software: Critical evaluation of the existing approaches and a new paradigm. ''OULU 2002'', 24 August 2002. Retrieved from http://jultika.oulu.fi/files/isbn9514267907.pdf.</ref>
 
The {{cite web|url=https://www.opengroup.org/forum/security/infosecmanagement|title=project}} looked at [[Capability Maturity Model Integration]], [[ISO 9000]], [[COBIT]], [[ITIL]], [[ISO/IEC 27001:2013]], and other standards, and found some potential for improvement in several fields, such as linking security to business needs, using a process based approach, providing some additional details (who, what, why) for implementation, and suggesting specific metrics, while preserving compatibility with the most popular IT and security management standards.
[[The Open Group]] provides O-ISM3 free of charge to organizations for their own internal noncommercial purposes.
 
== External linksAvailability ==
The Open Group provides the standard {{cite web|url=https://publications.opengroup.org/c17b|title=O-ISM3 v.20}} free of charge.
{{commons category|O-ISM3}}
 
*{{Unofficial website|http://www.ism3.com/}}
== References ==
*[https://www2.opengroup.org/ogsys/catalog/C102 O-ISM3 Online]
{{reflist|1}}
 
{{Open Group standards}}
 
[[Category:Data security]]
[[Category:Computer security]]
[[Category:Security]]
[[Category:Information governance]]