Towards ISO 27001 information Security certification

مقدم أطروحة جامعية

al-Fahli, Ouarda

مشرف أطروحة جامعية

Rashidi, Taj al-Din

الجامعة

جامعة الأخوين

الكلية

كلية الهندسة و العلوم

القسم الأكاديمي

شبكات الحاسوب

دولة الجامعة

المغرب

الدرجة العلمية

ماجستير

تاريخ الدرجة العلمية

2006

الملخص الإنجليزي

٥١^^ its decade of existence (1995-2006), A1 Akhawayn University in Ifiane’s (AUI) ٥^٠٠ and operations business have relied extensively on information technologies and systems.

The Universi^ acquired complex applications to manage its operational activities along with a collaborative environment and file sharing systems for its core mission that is Education.

Consequently, as information systems, technologies and services carry out all or most of لهe operations inside the University, they constitute an important point of failure that needs to be secured and protected.

In this perspective, and along with the enhancement of AUI networl، and IT facilities, the University, and mainly the Department of the Information Technologies and Services (ITS), felt the need of adopting a structured information securi^ plan following int«national standards.

This project aims at proposing a global fi^ameworl، for the Information Technology Security at AUI.

This framework is based on international standards for information security.

Applying this framework will, indeed, be ver^ beneficial to the University business and image on many aspects.

On the financial aspect, it will participate actively in the reduction of costs due to failures.

On the organi^tional and procedural aspects, this framework is providing a global view of all existing systems, their interfaces and interdependencies which will give place to £nte،prise هovernanءe.

On the technical aspect, this framework will help systems administrators The adoption of these standards does indeed constitute the beginning of a certification process for the University information system security.

This certification is an accreditation for excellence that recognises an Organisation as one that adheres to the best practices in managing security of its IT environment.

In order to select the more appropriate standard, a comparative study of a set of international standards has been conducted as a first step.

The standard (ISO 27001) is then chosen to define the global information securi^ management system, followed b^ a second standard (ISO 13335) which provides genera] guidelines for the implementation.

The second step was to conduct a prelimina^ audit in order to assess the existent and measure the gaps between the existent and best practices provided by ISO 2?001 based on guidelines proposed b^ IS© 13335.

This audit showed the absence of a global management system for information security including a documentation system.

In order to set up this management system, a baseline risk analysis was conducted, the results of which revealed problems of two di^erent aspects: The first problem concerns the lac^ of a structured operation environment for IT related systems.

The second problem which is more technical, concems some fiaws that were identified on the network.

To address these two problems, I proposed the adoption of a comprehensive documentary system composed of the Information Security ^^muel along with templates for policies, procedures and reporting documents.

I also develop«! a network monitoring tool to address some technical flaws that were detected.

التخصصات الرئيسية

العلوم التربوية
تكنولوجيا المعلومات وعلم الحاسوب

الموضوعات

عدد الصفحات

84

قائمة المحتويات

Table of contents.

Abstract.

Abstract in Arabic.

Chapter One : Introduction.

Chapter Two : Benchmarking of information security international standards.

Chapter Three : Applying the selected framework to the ITS department.

Chapter Four : Network monitoring tool.

Chapter Five : Conclusion and next steps.

References.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

al-Fahli, Ouarda. (2006). Towards ISO 27001 information Security certification. (Master's theses Theses and Dissertations Master). Al Akhawayn University, Morocco
https://search.emarefa.net/detail/BIM-644949

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

al-Fahli, Ouarda. Towards ISO 27001 information Security certification. (Master's theses Theses and Dissertations Master). Al Akhawayn University. (2006).
https://search.emarefa.net/detail/BIM-644949

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

al-Fahli, Ouarda. (2006). Towards ISO 27001 information Security certification. (Master's theses Theses and Dissertations Master). Al Akhawayn University, Morocco
https://search.emarefa.net/detail/BIM-644949

لغة النص

الإنجليزية

نوع البيانات

رسائل جامعية

رقم السجل

BIM-644949