Font Size: a A A

Design And Research For The Information Security Management System Of Shanghai Mobile

Posted on:2012-02-12Degree:MasterType:Thesis
Country:ChinaCandidate:X M ChengFull Text:PDF
GTID:2248330362967409Subject:Project management
Abstract/Summary:PDF Full Text Request
The development of telecommunications technology and revolution ofmanagement system promote the development of telecommunicationsoperation and maintenance system to the direction of centralization,standardization and informationization. As an important part oftelecommunications operation and maintenance system, information securitymanagement also faces the pressure from the aspects of technology andmanagement. On one hand, development of telecommunications technologyenhances the openness of network which closed before, enlarges the extent ofnew business, increases the risk of security; on the other hand, revolution ofmanagement system devastates the previously problems such as workscattering, lack of coordination, information security responsibility ambiguity.How to resolve such serious problems faced by information securitymanagement work? How to ensure the conduction of information securitywork in sequence and effective? It is an urgent mission to informationsecurity management work.After learning from process management and optimization theory, andsome international standards and best practices mode including ISO27001,ITIL, COBIT and etc., the author gives some helpful proposals forinformation security management of Shanghai Mobile.Firstly, the author discusses the system solution of Shanghai Mobileinformation security management flow system, and gives the detaileddescription; secondly, the author introduces the design and projectmanagement issues of one core process-security engineering constructionprocess in detail. Finally, the author gives a proposal of the information security process management platform. Through the establishment ofinformation security in the management of personnel, technical, institutionaland other organic elements organized, information system securitymanagement process supports the enterprise information securitymanagement work effectively.The innovative contents of this paper are:(1) Proposing an optimized mobile information security managementprocess which consists of15core processes according to "Structured LifeCycle" management information system development methodology. Thesystem establishes the correspondence between ISO27001and the securitywork, and makes it very convenient to analyze the difference between thesetwo, which will be helpful to the conduction of future security work.(2) Proposing an optimized design of the security engineeringconstruction process, which is a representative core process, and pointing outthe key points in project management from quality management, personnelmanagement, and procurement management. The achievement of threesynchronization work flow,"synchronized planning, synchronizedconstruction, synchronized operation and maintenance", makes it more securein the whole system life cycle.(3) Proposing a proposal for information security process managementplatform. The system will be helpful to management of securityprocess-related work and security decision-making.The proposals of this paper have been applied partly in the actual work. Itshows that systems construction and optimization of core processes haspositive effects on reducing business compliance risk, reducing security risksand decision supporting.
Keywords/Search Tags:Process Management, Information Security, System Development, Telecommunications Business
PDF Full Text Request
Related items