Security excellence from a total quality management approach

被引:10
|
作者
Martin, Clemens [1 ]
Bulkan, Anasuya [2 ]
Klempt, Philipp [2 ,3 ]
机构
[1] Baden Wuerttemberg Cooperat State Univ, Mannheim, Germany
[2] Univ Ontario, Inst Technol, Fac Business & IT, Oshawa, ON, Canada
[3] Ruhr Univ Bochum, Inst E Business Secur, Bochum, Germany
关键词
security excellence; business excellence; total quality management; European framework for quality management; control objectives for information and related technology; National Institute of Standards and Technology; ISO/IEC; 17799; security metrics; PERFORMANCE; TECHNOLOGY;
D O I
10.1080/14783363.2010.545556
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
This paper focuses on the synergy of business and security requirements to create a holistic methodology or approach. The integration revolves around the concept of total quality management to measure the security posture and is based on the premise that security requirements must be aligned and fused with the business' objectives. The postulated security methodology has extended the total quality management and business excellence philosophies to create a new security excellence approach. The American National Institute of Standards and Technology's metrics are used as benchmarks to determine the security areas that should be addressed while the European Framework for Quality Management is used to reflect the integration with the National Institute of Standards and Technology's metrics and to represent the domains in a business excellence approach. The fusion is then extended to the Control Objectives for Information and Related Technology and, finally, to the international Standard ISO/IEC 17799 (Information technology - security techniques - Code of practice for information security management) to depict the merger between security and business domains along a TQM approach and to be transferable to any standard or regulation by being able to incorporate acceptable security requirements into the underlying framework.
引用
收藏
页码:345 / 371
页数:27
相关论文
共 50 条
  • [31] Conceptualizing total quality management in engineering education and developing a TQM educational excellence model
    Sakthivel, P. B.
    Raju, R.
    [J]. TOTAL QUALITY MANAGEMENT & BUSINESS EXCELLENCE, 2006, 17 (07) : 913 - 934
  • [32] FROM QUALITY-CONTROL TO TOTAL QUALITY MANAGEMENT
    BELTRAMI, G
    MARESCA, ES
    [J]. MICROCHEMICAL JOURNAL, 1992, 45 (03) : 310 - 317
  • [33] Total quality management culling approach for dairy farms
    Faust, MA
    Sischo, B
    [J]. LARGE ANIMAL PRACTICE, 1997, 18 (03): : 11 - 12
  • [34] SURVIVE BUSINESS CHALLENGES WITH THE TOTAL QUALITY MANAGEMENT APPROACH
    DEDHIA, NS
    [J]. TOTAL QUALITY MANAGEMENT, 1995, 6 (03): : 265 - 272
  • [35] REDESIGNING WORKFLOW USING A TOTAL QUALITY MANAGEMENT APPROACH
    MARCIANO, K
    FRAUENHOFER, S
    NEWBY, M
    SCHAKE, D
    WOWKOWYCH, J
    MCMICAN, A
    [J]. TRANSFUSION, 1993, 33 (09) : S84 - S84
  • [36] TOTAL QUALITY MANAGEMENT - AN APPROACH AND A CASE-STUDY
    ALY, NA
    MAYTUBBY, VJ
    ELSHENNAWY, AK
    [J]. COMPUTERS & INDUSTRIAL ENGINEERING, 1990, 19 (1-4) : 111 - 116
  • [37] Business excellence through quality management
    Vora, MK
    [J]. TOTAL QUALITY MANAGEMENT, 2002, 13 (08): : 1151 - 1159
  • [38] THE GOAL OF RESEARCH MANAGEMENT EXCELLENCE OR QUALITY?
    Guedon, Jean-Claude
    [J]. EDUWEB-REVISTA DE TECNOLOGIA DE INFORMACION Y COMUNICACION EN EDUCACION, 2013, 7 : 63 - 92
  • [39] Leadership strategies for gaining business excellence through total quality management: a Finnish case study
    Savolainen, T
    [J]. TOTAL QUALITY MANAGEMENT, 2000, 11 (02): : 211 - 226
  • [40] The golden integral quality approach: From management of quality to quality of management
    Galetto, F
    [J]. TOTAL QUALITY MANAGEMENT, 1999, 10 (01): : 17 - 35