Information security of Web-based systems in Iran Institution of public libraries

Purpose: This paper aims to evaluate the security of web-based information systems of Iran Public Libraries Foundation (IPLF). Methodology: Survey method was used as a method for implementation. The tool for data collection was a questionnaire, based on the standard ISO/IEC 27002, that has the eleve...

Full description

Bibliographic Details
Main Authors: morteza kokabi, mansor kohi rostami
Format: Article
Language:fas
Published: Iran Public Libraries Foundation 2015-06-01
Series:تحقیقات اطلاع‌رسانی و کتابخانه‌های عمومی
Subjects:
Online Access:http://publij.ir/article-1-1077-en.html
_version_ 1827585123878436864
author morteza kokabi
mansor kohi rostami
author_facet morteza kokabi
mansor kohi rostami
author_sort morteza kokabi
collection DOAJ
description Purpose: This paper aims to evaluate the security of web-based information systems of Iran Public Libraries Foundation (IPLF). Methodology: Survey method was used as a method for implementation. The tool for data collection was a questionnaire, based on the standard ISO/IEC 27002, that has the eleven indicators and 79 sub-criteria, which examines security of web-based information systems of IPLF. Four web-based systems of IPLF evaluated. Evaluation criteria includes: Security Policy; Organization of information security; Asset management; human resources security; physical and environmental security; communications and operations management; access control; Information systems acquisition, development and maintenance; Information security incident management; business continuity management, and compliance. Findings: Results show that security level of "Reading grid system" and "my book system" with an average of 0/68 was high. Security level of “Payam Mashregh system” and “Farzin statistical system” with an average of 0/60 and 0/53 was middle. Indicators such as "business continuity management", “prepare, develop and maintain information systems' strongest points”, “information security policy” and “information security organization” are among the most vulnerable areas of information security systems of IPLF And there were significant differences between viewpoints of experts about indicators of Information Security systems of IPLF. Originality/value: We designed a systematic approach for the immunization of data exchange environment by evaluating web-based systems of IPLF by some criteria derived from accepted information security management standards. This article identified the strengths and vulnerabilities of the mentioned systems.
first_indexed 2024-03-08T23:41:07Z
format Article
id doaj.art-c6e91c9193eb40e1bf78c6ee054c24c6
institution Directory Open Access Journal
issn 2645-5730
2645-6117
language fas
last_indexed 2024-03-08T23:41:07Z
publishDate 2015-06-01
publisher Iran Public Libraries Foundation
record_format Article
series تحقیقات اطلاع‌رسانی و کتابخانه‌های عمومی
spelling doaj.art-c6e91c9193eb40e1bf78c6ee054c24c62023-12-14T05:12:23ZfasIran Public Libraries Foundationتحقیقات اطلاع‌رسانی و کتابخانه‌های عمومی2645-57302645-61172015-06-0121189107Information security of Web-based systems in Iran Institution of public librariesmorteza kokabi0mansor kohi rostami1 Purpose: This paper aims to evaluate the security of web-based information systems of Iran Public Libraries Foundation (IPLF). Methodology: Survey method was used as a method for implementation. The tool for data collection was a questionnaire, based on the standard ISO/IEC 27002, that has the eleven indicators and 79 sub-criteria, which examines security of web-based information systems of IPLF. Four web-based systems of IPLF evaluated. Evaluation criteria includes: Security Policy; Organization of information security; Asset management; human resources security; physical and environmental security; communications and operations management; access control; Information systems acquisition, development and maintenance; Information security incident management; business continuity management, and compliance. Findings: Results show that security level of "Reading grid system" and "my book system" with an average of 0/68 was high. Security level of “Payam Mashregh system” and “Farzin statistical system” with an average of 0/60 and 0/53 was middle. Indicators such as "business continuity management", “prepare, develop and maintain information systems' strongest points”, “information security policy” and “information security organization” are among the most vulnerable areas of information security systems of IPLF And there were significant differences between viewpoints of experts about indicators of Information Security systems of IPLF. Originality/value: We designed a systematic approach for the immunization of data exchange environment by evaluating web-based systems of IPLF by some criteria derived from accepted information security management standards. This article identified the strengths and vulnerabilities of the mentioned systems.http://publij.ir/article-1-1077-en.htmlinformation securitystandard iso / iec 27002web based systemsiran public libraries foundation
spellingShingle morteza kokabi
mansor kohi rostami
Information security of Web-based systems in Iran Institution of public libraries
تحقیقات اطلاع‌رسانی و کتابخانه‌های عمومی
information security
standard iso / iec 27002
web based systems
iran public libraries foundation
title Information security of Web-based systems in Iran Institution of public libraries
title_full Information security of Web-based systems in Iran Institution of public libraries
title_fullStr Information security of Web-based systems in Iran Institution of public libraries
title_full_unstemmed Information security of Web-based systems in Iran Institution of public libraries
title_short Information security of Web-based systems in Iran Institution of public libraries
title_sort information security of web based systems in iran institution of public libraries
topic information security
standard iso / iec 27002
web based systems
iran public libraries foundation
url http://publij.ir/article-1-1077-en.html
work_keys_str_mv AT mortezakokabi informationsecurityofwebbasedsystemsiniraninstitutionofpubliclibraries
AT mansorkohirostami informationsecurityofwebbasedsystemsiniraninstitutionofpubliclibraries