Peer Reviewed Journal via three different mandatory reviewing processes, since 2006, and, from September 2020, a fourth mandatory peer-editing has been added.
Many international standards exist in the field of IT security.
This research is based on the ISO/IEC 15408, 15446, 19791,
13335 and 17799 standards. In this paper, we propose a
knowledge base comprising a threat countermeasure model
based on international standards for identifying and specifying
threats which affect IT environments. In addition, the proposed
knowledge base system aims at fusing similar security control
policies and objectives in order to create effective security
guidelines for specific IT environments. As a result, a
knowledge base of security objectives was developed on the
basis of the relationships inside the standards as well as the
relationships between different standards. In addition, a web
application was developed which displays details about the
most common threats to information systems, and for each
threat presents a set of related security control policies from
different international standards, including ISO/IEC 27002.