Security Management Life Cycle (SMLC): A Comparative Study

被引:0
|
作者
Choobineh, Joobin [1 ]
Anderson, Evan [1 ]
Grimaila, Michael R. [2 ]
机构
[1] Texas A&M Univ, Mays Business Sch, Informat & Operat Management, College Stn, TX 77843 USA
[2] Air Force Inst Technol, Ctr Cyberspace Res, Wright Patterson AFB, OH USA
来源
关键词
Security Management; Security Life Cycle; IT Management; COSO; COBIT; ITIL;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We introduce an integrated conceptualization of enterprise information technology security management in the form of a life cycle that accounts for the people, processes, infrastructure, and applications within an enterprise. Our life cycle view provides a lens through which one can view the security management activities at the strategic, tactical, and operational levels with regard to their strategic alignment with organizational goals. We compare and contrast three widely adopted frameworks (COSO, COBIT and ITIL) for enterprise risk and IT management with respect to our life cycle. We conclude that although the definitions of each stage of the life cycle are similar in these frameworks, their approach, philosophy, and method of execution is primarily determined by their unique focus. By developing a life cycle abstraction which encapsulates all of these frameworks, security management can better understand how their responsibilities and activities support organizational objectives.
引用
收藏
页数:10
相关论文
共 50 条
  • [1] The applicability of System Migration Life Cycle (SMLC) framework
    Althani, Bashair
    Khaddaj, Souheil
    [J]. 2017 16TH INTERNATIONAL SYMPOSIUM ON DISTRIBUTED COMPUTING AND APPLICATIONS TO BUSINESS, ENGINEERING AND SCIENCE (DCABES), 2017, : 141 - 144
  • [2] IS security management framework: A comprehensive life cycle perspective
    Warkentin, M
    Schmidt, MB
    Johnston, AC
    Boren, M
    [J]. INNOVATIONS THROUGH INFORMATION TECHNOLOGY, VOLS 1 AND 2, 2004, : 471 - 474
  • [3] Security risks: Management and mitigation in the software life cycle
    Gilliam, DP
    [J]. THIRTEENTH IEEE INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, PROCEEDINGS, 2004, : 211 - 216
  • [4] Study on the Life Cycle Security Risks Management of Large-scale Public Buildings
    Han Guo-bo
    Gao Quan-chen
    [J]. ENGINEERING SOLUTIONS FOR MANUFACTURING PROCESSES, PTS 1-3, 2013, 655-657 : 2209 - +
  • [5] Comparative life cycle assessment of sludge management: A case study of Xiamen, China
    Xiao Lishan
    Lin Tao
    Wang Yin
    Ye Zhilong
    Liao Jiangfu
    [J]. JOURNAL OF CLEANER PRODUCTION, 2018, 192 : 354 - 363
  • [6] Security and trust in cloud application life-cycle management
    Albanese, Massimiliano
    De Benedictis, Alessandra
    de Macedo, Douglas D. J.
    Messina, Fabrizio
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2020, 111 : 934 - 936
  • [7] Comparative life cycle assessment of biowaste to resource management systems - A Danish case study
    Thomsen, M.
    Seghetta, M.
    Mikkelsen, M. H.
    Gyldenkaerne, S.
    Becker, T.
    Caro, D.
    Frederiksen, P.
    [J]. JOURNAL OF CLEANER PRODUCTION, 2017, 142 : 4050 - 4058
  • [8] Reputation Management in Societal Security: A Comparative Study
    Christensen, Tom
    Lodge, Martin
    [J]. AMERICAN REVIEW OF PUBLIC ADMINISTRATION, 2018, 48 (02): : 119 - 132
  • [9] A comparative study of pump life cycle costs
    Hennecke, F.-W.
    [J]. Paper Technology, 2006, 47 (07): : 20 - 27
  • [10] The comparative study on model of brand life cycle
    Huang Jie
    Zhang Guoliang
    [J]. PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INNOVATION & MANAGEMENT, VOLS I AND II, 2007, : 2517 - 2521