Comparative Analysis of Methods for Assessing Confidence in the Information Security Audit Process
摘要
The analysis of existing methods for assessing confidence in the information security audit process has been carried out. The analysis revealed a number of shortcomings that lead to the impossibility of implementing the process of assessing confidence in the information security audit process at any time due to the high cost of effort and resources for the organization and constant maintenance of the confidence assessment process, as well as due to the low level of automation and the need to attract experts to conduct conformity assessment. The method of trust assessment to the information security audit process, developed by the authors, is proposed, aimed at the complex analysis of the audit process itself, and based on the analysis of a predetermined set of evidence of trust according to predetermined criteria of trust assessment with wide opportunities for automation and optimization of time, effort and resources for the preparation and conduct of the process of trust assessment to the audit process. The proposed approach to assessing trust in the information security audit process together with the approaches to assessing trust in other information security processes being developed solves the issue of forming a trusted interaction between the subjects of information exchange in order to ensure confidence that each participant of information exchange will not lead to the realization of information security risks.