Security excellence from a total quality management approach

被引:10
|
作者
Martin, Clemens [1 ]
Bulkan, Anasuya [2 ]
Klempt, Philipp [2 ,3 ]
机构
[1] Baden Wuerttemberg Cooperat State Univ, Mannheim, Germany
[2] Univ Ontario, Inst Technol, Fac Business & IT, Oshawa, ON, Canada
[3] Ruhr Univ Bochum, Inst E Business Secur, Bochum, Germany
关键词
security excellence; business excellence; total quality management; European framework for quality management; control objectives for information and related technology; National Institute of Standards and Technology; ISO/IEC; 17799; security metrics; PERFORMANCE; TECHNOLOGY;
D O I
10.1080/14783363.2010.545556
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
This paper focuses on the synergy of business and security requirements to create a holistic methodology or approach. The integration revolves around the concept of total quality management to measure the security posture and is based on the premise that security requirements must be aligned and fused with the business' objectives. The postulated security methodology has extended the total quality management and business excellence philosophies to create a new security excellence approach. The American National Institute of Standards and Technology's metrics are used as benchmarks to determine the security areas that should be addressed while the European Framework for Quality Management is used to reflect the integration with the National Institute of Standards and Technology's metrics and to represent the domains in a business excellence approach. The fusion is then extended to the Control Objectives for Information and Related Technology and, finally, to the international Standard ISO/IEC 17799 (Information technology - security techniques - Code of practice for information security management) to depict the merger between security and business domains along a TQM approach and to be transferable to any standard or regulation by being able to incorporate acceptable security requirements into the underlying framework.
引用
收藏
页码:345 / 371
页数:27
相关论文
共 50 条