Accession Number : ADA441305

Title :   Information Asset Profiling

Descriptive Note : Final rept.

Corporate Author : CARNEGIE-MELLON UNIV PITTSBURGH PA SOFTWARE ENGINEERING INST

Personal Author(s) : Stevens, James F. ; Caralli, Richard A. ; Willke, Bradford J.

PDF Url : ADA441305

Report Date : JUN 2005

Pagination or Media Count : 62

Abstract : The steadily increasing technical and environmental complexity of today's globally networked economy presents many obstacles to organizations as they attempt to protect their information assets. Information assets are constantly processed and combined to form new information assets. The line between ownership and custodianship of information assets blurs as information freely flows throughout an organization and often crosses outside organizational boundaries to other entities such as partners, customers, and suppliers. The CERT Survivable Enterprise Management group at the Software Engineering Institute developed the Information Asset Profiling (IAP) process as a tool to help organizations begin to address these security challenges. The authors describe IAP, a documented and repeatable process for developing consistent asset profiles. They also explain how the development of an information asset inventory using the IAP process provides a strong basis for organizations to begin to identify and address their information security needs.

Descriptors :   *SOFTWARE ENGINEERING, *REQUIREMENTS, *INFORMATION SYSTEMS, *PROFILES, *DATA PROCESSING SECURITY, *INFORMATION SECURITY, ORGANIZATIONS, INVENTORY, RISK MANAGEMENT

Subject Categories : Computer Programming and Software
      Computer Systems Management and Standards

Distribution Statement : APPROVED FOR PUBLIC RELEASE