Show simple item record

dc.contributor.advisorMichael Cusumano.en_US
dc.contributor.authorSharma, Dhirendra, S.M. Massachusetts Institute of Technologyen_US
dc.contributor.otherSystem Design and Management Program.en_US
dc.date.accessioned2011-12-09T21:25:42Z
dc.date.available2011-12-09T21:25:42Z
dc.date.copyright2011en_US
dc.date.issued2011en_US
dc.identifier.urihttp://hdl.handle.net/1721.1/67568
dc.descriptionThesis (S.M. in Engineering and Management)--Massachusetts Institute of Technology, Engineering Systems Division, System Design and Management Program, 2011.en_US
dc.descriptionCataloged from PDF version of thesis.en_US
dc.descriptionIncludes bibliographical references (p. 124-130).en_US
dc.description.abstractThere are several technological solutions available in the market to help organizations with information security breach detection and prevention such as intrusion detection and prevention systems, antivirus software, firewalls, and spam filters. There is no doubt in the fact that significant progress has been made in the technological side of information security. However, when we study causes of information security breaches, we find that a significant number are caused by non-technical reasons such as social engineering, theft of computing device or portable hard drive, human behavior, and human error. This leads us to conclude that information security should not be viewed through technology perspective only. Instead, a more holistic approach is required. This thesis provides a systems approach towards information security management and include technological, management and social aspects. This thesis starts with introduction especially background and motivation of the author, followed by literature research. Next, Enterprise Information Security Management Framework is presented leading to estimation of an organization's information security management maturity-level. Finally, conclusion and potential future work are presented.en_US
dc.description.statementofresponsibilityby Dhirendra Sharma.en_US
dc.format.extent130 p.en_US
dc.language.isoengen_US
dc.publisherMassachusetts Institute of Technologyen_US
dc.rightsM.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission.en_US
dc.rights.urihttp://dspace.mit.edu/handle/1721.1/7582en_US
dc.subjectEngineering Systems Division.en_US
dc.subjectSystem Design and Management Program.en_US
dc.titleEnterprise Information Security Management Framework [EISMF]en_US
dc.title.alternativeEISMFen_US
dc.typeThesisen_US
dc.description.degreeS.M.in Engineering and Managementen_US
dc.contributor.departmentSystem Design and Management Program.en_US
dc.contributor.departmentMassachusetts Institute of Technology. Engineering Systems Division
dc.identifier.oclc761731123en_US


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record