TARU PUBLICATIONS
Journal of Discrete Mathematical Sciences and Cryptography cover
Open Access ·Peer-reviewed·ISSN (Online): 2169-0065·ISSN (Print): 0972-0529

Monthly Journal: Publishes theoretical and applied research in all areas of Discrete Mathematical Sciences, Cryptography, Combinatorics, Elliptic Curves and Information Security.

Issues up to 2022 co-published with and available at:Taylor & Francis Online
submissions@tarupublications.com
Open Access Research Article

Design & analysis of novel IT security framework for overcoming data security & privacy challenges

* , ,

* Corresponding author · click or hover a name for details

pp. 885–898Vol. 26Issue 3April 2023DOI: 10.47974/JDMSC-1776 Crossmark XML
Published Online:
01 Apr 2023
Article type:
Research Article
Language:
EN
Article no.:
JDMSC-1776
Pages:
885–898

Abstract

IT security has always been a major concern for all organizations, especially after the rise in IT Integration amongst all processes, Post pandemic this has become a bigger issue than earlier. The organizations are growing also with IT Integration the negative impact of information related risk incidents are also increasing worldwide. There are several IT Risk Assessment Frameworks in use to address information security assaults, vulnerabilities, threats, and breaches, including ISO 270001/27005. COBIT, NIST SP- 800/53 etc, though following and implementation of these protocols, still organizations face challenges of IT risk, which may involve an asset or information. The biggest challenge is the data Security or privacy. Based on survey data, this study evaluates the majority of the current IT risk management frameworks and makes an effort to pinpoint any shortcomings in them. Based on the analysis done, a new IT Security framework is proposed and implemented in two organizations for its detailed analysis and validations with the existing models For the Risk Assessment of the same organization new technique for IT Risk Assessment is also proposed.

Keywords

Subject Classifications

68M2568P27

References

[1] Allen, Julia H. : Governing for Enterprise Security. Carnegie Mellon University. Report (2018). https://doi.org/10.1184/R1/6573995.v1
[2] Patrick MachariaNjorogeet. Al. A framework for effective information security risk management in kenyan public universities, IJSSIT, Volume IV, ISSUE X (2019).
[3] https://www.educause.edu/focus-areas-and-initiatives/policy-and-security/cybersecurity-program/resources/information-security-guide/toolkits/information-security-governance.
[4] https://www.diligent.com/en-gb/blog/information-security-governance-best-practices/.
[5] https://www.iso.org/standard/42103.html#:~:text=ISO%2FIEC%2027001%3A2005% 20specifies,the%20organization’s%20overall%20business%20risks.
[6] https://www.foundpg.com/iso-31000.
[7] NIST US, Information Security, Managing Information Security Risk Organization, Mission, and Information System View, Special Publication 800-39 (2017).
[8] Kidd Chrissy, BMC Blogs (2019). (https://www.bmc.com/blogs/cobit/).
[9] Prashant Manuja & Rajveer Singh Shekhawat. Developing information security metrics and measures for risk assessment of an organization, Journal of Discrete Mathematical Sciences and Cryptography, 25:4, 1195-1202 (2022), DOI: 10.1080/09720529.2022.2075092.
[10] YashpalSoni, GeetaChhabra Gandhi & Dinesh Goyal. Improved and secure framework for existing e-Bazaar model in Rajasthan, Journal of Information and Optimization Sciences, 43:8, 1975-1985 (2022), DOI: 10.1080/02522667.2022.2111042.
[11] YashpalSoni, GeetaChhabra Gandhi & Dinesh Goyal. A secure e-health framework for rural Rajasthan, Journal of Statistics and Management Systems, 25:8, 2113-2122 (2022), DOI: 10.1080/09720510.2022.2119000.

Views: 196Downloads: 5Citations: 0