Millennium. Communications of the ACM, 2000. 43(7): p. 125-128.
3. Park, C.-S., S.-S. Jang, and Y.-T. Park, A Study of Effect of Information Security Manage-
ment System[ISMS] Certification on Organization Performance. IJCSNS International
Journal of Computer Science and Network Security., 2010. 10(3): p. 10-21.
4. Barlette, Y. and V. Vladislav. Exploring the Suitability of IS Security Management Stan-
dards for SMEs. in Hawaii International Conference on System Sciences, Proceedings of
the 41st Annual. 2008. Waikoloa, HI, USA.
5. Fal, A.M., Standardization in information security management Cybernetics and Systems
Analysis 2010. 46(3): p. 181-184.
6. Wiander, T. and J. Holappa, Theoretical Framework of ISO 17799 Compliant. Information
Security Management System Using Novel ASD Method., in Technical Report, V.T.R.C.o.
Finland, Editor. 2006.
7. Wiander, T. Implementing the ISO/IEC 17799 standard in practice – experiences on audit
phases. in AISC '08: Proceedings of the sixth Australasian conference on Information secu-
rity. 2008. Wollongong, Australia.
8. Yao, L., Discussion on Effectiveness Measurement in ISMS: Based on Analysis of ISMS
Effectiveness Measurement in ISO/IEC 27004:2009. Electronic Product Reliability and En-
vironmental, 2010.
9. ISO/IEC27004, ISO/IEC FCD 27004, Information Technology - Security Techniques -
Information Security Metrics and Measurement (under development). 2009.
10. Sánchez, L.E., et al. Security Management in corporative IT systems using maturity mod-
els, taking as base ISO/IEC 17799. in International Symposium on Frontiers in Availabili-
ty, Reliability and Security (FARES’06) in conjunction with ARES. 2006. Viena (Austria).
11. Sánchez, L.E., et al. MMISS-SME Practical Development: Maturity Model for Information
Systems Security Management in SMEs. in 9th International Conference on Enterprise In-
formation Systems (WOSIS’07). 2007b. Funchal, Madeira (Portugal). June.
12. Sánchez, L.E., et al. Developing a model and a tool to manage the information security in
Small and Medium Enterprises. in International Conference on Security and Cryptography
(SECRYPT’07). 2007a. Barcelona. Spain.: Junio.
13. Sánchez, L.E., et al. Developing a maturity model for information system security man-
agement within small and medium size enterprises. in 8th International Conference on En-
terprise Information Systems (WOSIS’06). 2006. Paphos (Chipre). March.
14. Sánchez, L.E., et al. SCMM-TOOL: Tool for computer automation of the Information Secu-
rity Management Systems. in 2nd International conference on Software and Data Technol-
ogies (ICSOFT‘07). . 2007c. Barcelona-España Septiembre.
166