📢 Latest Update: UGC Discontinues CARE Journal Listing: New Guidelines for Selecting Peer-Reviewed Journals View Now

International Journal of Information Security Engineering Cover

International Journal of Information Security Engineering

E-ISSN: 3049-1150 | Peer-Reviewed Journal (Refereed Journal) | Hybrid Open Access

About the Journal

International Journal of Information Security Engineering

International Journal of Information Security Engineering is a peer-reviewed online journal launched in 2023 have earned a reputation for editorial excellence and is creating an impact on the research community. Journal focuses on providing practical usable information in the field of network security. The papers included in this journal are original research articles and editorial reviews of exceptional quality.

Focus & Scope

  • Information security governance and risk management: security strategy and programme design, risk identification, assessment, and treatment methodologies, information asset classification and ownership, security metrics and reporting to leadership, third-party and supply chain risk, and security investment and economics.
  • Standards, compliance, and audit: implementation of information security management systems, control framework mapping and gap analysis, regulatory and data protection compliance, continuous compliance monitoring and automated control testing, audit evidence collection, and certification readiness.
  • Security architecture and engineering: enterprise security architecture design, defence in depth and zero trust models, secure system and service design patterns, security service layers in distributed and service-oriented systems, segmentation and trust boundary design, and security in embedded and control system architectures.
  • Identity and access management: role-based, attribute-based, and policy-based access control models, context-aware and adaptive authorisation, privileged access management, federated identity and single sign-on, identity lifecycle and joiner-mover-leaver processes, and entitlement review and certification.
  • Applied cryptography in practice: selection and deployment of cryptographic primitives, key management lifecycle and hardware security modules, certificate and public key infrastructure operations, encryption of data at rest and in transit, cryptographic agility and post-quantum migration planning, and common implementation failures.
  • Offensive security and penetration testing: penetration testing methodology and scoping, web and application security testing, injection and authentication flaw discovery, automated scanning and false positive reduction, red teaming and adversary emulation, and responsible disclosure and ethical frameworks.
  • Vulnerability and threat management: vulnerability discovery, triage, and prioritisation, exploitability and severity scoring, patch management practice and effectiveness, threat intelligence collection and enrichment, open source and social media as intelligence sources, and vulnerability database and advisory analysis.
  • Security operations and monitoring: security operations centre design and workflow, log collection, normalisation, and correlation, detection engineering and alert tuning, automation and orchestration of response, metrics for detection and response performance, and analyst workload and alert fatigue.
  • Incident response and digital forensics: incident classification and escalation, containment, eradication, and recovery practice, disk, memory, and network forensics, evidence handling and chain of custody, cloud and mobile forensics, and post-incident review and organisational learning.
  • Application and software security: secure development lifecycle integration, threat modelling methodologies, static and dynamic application security testing, dependency and software composition analysis, security in continuous delivery pipelines, and secure coding practice and developer enablement.
  • Platform and infrastructure security: operating system hardening and baseline configuration, endpoint protection and detection, cloud security posture and misconfiguration, container and workload security, backup and recovery integrity, and secure administration practice.
  • Data protection and privacy engineering: data discovery and classification, data loss prevention, anonymisation and pseudonymisation techniques, privacy impact assessment, retention and disposal practice, and cross-border data transfer controls.
  • Human and organisational factors: security awareness and behaviour change, social engineering and phishing resistance, insider threat detection and management, security culture measurement, and usability of security controls.

Keywords

Information Security, Risk Management, Security Governance, Penetration Testing, Digital Forensics, Access Control, Security Compliance, Threat Intelligence, Vulnerability Management, Security Operations

No Entries Found
]
No Entries Found
]
Support