An Overview of Information Security Governance

被引:0
|
作者
Asgarkhani, Mehdi [1 ]
Correia, Eduardo [1 ]
Sarkar, Amit [1 ]
机构
[1] Ara Inst Canterbury, Dept Comp, Christchurch, New Zealand
关键词
IT Governance; Risk Management; Information Security Governance; Security Standards;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
IT Governance spans the culture, organization, policy and practices that provide for IT management and control across five key functions including Strategic Alignment, Value Delivery, Resource Management, Performance Management, and Risk Management. The risk management function is concerned with ascertaining that procedures are defined for ensuring that risks have been sufficiently managed, as well as including assessing the risk factors of IT investments. The increased use of networking solutions has meant that the key aspect of risk management function of IT Governance is focused on managing information and network security. The internet has progressed to become the common platform for connecting businesses and communities worldwide. Transferring information through the internet amid sophisticated networked systems and applications is a norm. While some previous research has identified the need for protective measures in operating networked systems, security management of information and networked systems is essential. This paper examines previous research on technology governance, risk management, and IT security management by using a broad risk management framework.
引用
收藏
页数:4
相关论文
共 50 条
  • [1] Information Security Governance
    Williams, Paul
    [J]. 2001, Elsevier Ltd (06): : 60 - 70
  • [2] INFORMATION SECURITY - AN OVERVIEW
    ANDREASSEN, AL
    LEIGHTON, WJ
    SCHREIBER, DF
    [J]. AT&T TECHNICAL JOURNAL, 1988, 67 (03): : 2 - 8
  • [3] Applying information security governance
    Moulton, R
    Coles, RS
    [J]. COMPUTERS & SECURITY, 2003, 22 (07) : 580 - 584
  • [4] Information security governance framework
    Faculty of Informatics, Kogakuin University, Japan
    不详
    不详
    不详
    不详
    不详
    [J]. Proc ACM Conf Computer Commun Secur, (1-5):
  • [5] An information security governance framework
    Da Veiga, A.
    Eloff, J. H. P.
    [J]. INFORMATION SYSTEMS MANAGEMENT, 2007, 24 (04) : 361 - 372
  • [6] Corporate governance and information security
    von Solms, B
    [J]. COMPUTERS & SECURITY, 2001, 20 (03) : 215 - 218
  • [7] A framework for the governance of information security
    Posthumus, S
    von Solms, R
    [J]. COMPUTERS & SECURITY, 2004, 23 (08) : 638 - 646
  • [8] Improved Security through Information Security Governance
    Johnston, Allen C.
    Hale, Ron
    [J]. COMMUNICATIONS OF THE ACM, 2009, 52 (01) : 126 - 129
  • [9] Overview of security of information system
    Sekimoto, Mitsugu
    Sakurai, Keita
    [J]. Kyokai Joho Imeji Zasshi/Journal of the Institute of Image Information and Television Engineers, 2002, 56 (07):
  • [10] The Complexity of Global Security Governance: An Analytical Overview
    Kavalski, Emilian
    [J]. GLOBAL SOCIETY, 2008, 22 (04) : 423 - 443