论文标题
ISMS在改善SOC中与数字取证相关的过程改善中的作用
ISMS role in the improvement of digital forensics related process in SOC's
论文作者
论文摘要
关注数字或计算机取证能力的组织建立程序和记录以支持计算机犯罪的起诉可能会受益于实施ISO 27001:2013-Compliant(ISMS信息安全管理系统)。经过认证的ISM为在数字取证调查中收集的信息增加了信誉;认证表明,该组织有一个局外人,可以验证正确的程序是否到位并遵循。在起诉入侵者或客户或其他利益相关者向组织寻求损害时,认证的ISMS是一种有价值的工具。 SOC(安全操作中心)作为组织或处理大量信息的安全部门需要管理补充,而ISMS将是一个不错的选择。这个想法将有助于找到与非云和云数字取证有关的与数字取证有关的问题的解决方案,包括与不同CSP之间缺乏标准化有关的问题(云服务提供商)。
Organizations concerned about digital or computer forensics capability which establishes procedures and records to support a prosecution for computer crimes could benefit from implementing an ISO 27001: 2013-compliant (ISMS Information Security Management System). A certified ISMS adds credibility to information gathered in a digital forensics investigation; certification shows that the organization has an outsider which verifies that the correct procedures are in place and being followed. A certified ISMS is a valuable tool either when prosecuting an intruder or when a customer or other stakeholder seeks damages against the organization. SOC (Security Operation Center) as an organization or a security unit which handles a large volume of information requires a management complement, where ISMS would be a good choice. This idea will help finding solutions for problems related to digital forensics for non-cloud and cloud digital forensics, including Problems associated with the absence of standardization amongst different CSPs (Cloud service providers).