Architecture of Information Security Policies: A Content Analysis

被引:1
|
作者
Lopes, Isabel [1 ,2 ]
Oliveira, Pedro [2 ]
机构
[1] Univ Minho, Ctr ALGORITMI, Braga, Portugal
[2] Polytech Inst Braganca, Sch Technol & Management, Braganca, Portugal
关键词
Features and Components of Information Security Policies; Information Security; Small and Medium Sized Enterprises;
D O I
10.1007/978-3-319-31232-3_46
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The growing importance that Information Systems (IS) have in our companies naturally brings about a need to rely and trust in their use. There are a number of technologies which help ensure the security and trust in the IS use. However, technology alone does not solve all the problems, which is why there is a need for well-defined information systems security policies in order to ensure the data integrity and confidentiality. Nevertheless, there is a lack of information concerning the contents that such policies must have. This work aims to contribute to the filling of this gap. It presents a synthesis of the literature on information security policies content and it characterizes 15 Small and Medium Sized Enterprises (SMEs) information security policy documents as far as their features and components are concerned. The content analysis (CA) research technique was applied to characterize the information security policies. The profile of the policies is presented and discussed and propositions are made for possible future works.
引用
收藏
页码:493 / 502
页数:10
相关论文
共 50 条
  • [1] Semantically Sound Analysis of Content Security Policies
    Calzavara, Stefano
    Rabitti, Alvise
    Bugliesi, Michele
    [J]. FORMAL TECHNIQUES FOR DISTRIBUTED OBJECTS, COMPONENTS, AND SYSTEMS (FORTE 2019), 2019, 11535 : 293 - 297
  • [2] Content Analysis of Indonesian National Security Architecture
    Surwandono
    Ramadhani, Masyithoh Annisa
    [J]. PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON ETHICS IN GOVERNANCE (ICONEG 2016), 2016, 84 : 138 - 142
  • [3] Complex Security Policy? A Longitudinal Analysis of Deployed Content Security Policies
    Roth, Sebastian
    Barron, Timothy
    Calzavara, Stefano
    Nikiforakis, Nick
    Stock, Ben
    [J]. 27TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2020), 2020,
  • [4] The information security policy unpacked: A critical study of the content of university policies
    Doherty, Neil Francis
    Anastasakis, Leonidas
    Fulford, Heather
    [J]. INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2009, 29 (06) : 449 - 457
  • [5] Qualitative content analysis of actionable advice in information security policies - introducing the keyword loss of specificity metric
    Rostami, Elham
    Karlsson, Fredrik
    [J]. INFORMATION AND COMPUTER SECURITY, 2024, 32 (04) : 492 - 508
  • [6] Do Information Security Policies Reduce the Incidence of Security Breaches: An Exploratory Analysis
    Doherty, Neil
    Fulford, Heather
    [J]. INFORMATION RESOURCES MANAGEMENT JOURNAL, 2005, 18 (04) : 21 - 39
  • [7] Writing information security policies
    Zegiorgis, S
    [J]. TECHNICAL COMMUNICATION, 2002, 49 (03) : 357 - 357
  • [8] Owned policies for information security
    Chen, HB
    Chong, S
    [J]. 17TH IEEE COMPUTER SECURITY FOUNDATIONS WORKSHOP, PROCEEDINGS, 2004, : 126 - 138
  • [9] Practice-based discourse analysis of information security policies
    Karlsson, Fredrik
    Hedstrom, Karin
    Goldkuhl, Goran
    [J]. COMPUTERS & SECURITY, 2017, 67 : 267 - 279
  • [10] Ontology-based Information Content Security Analysis
    Yan, Pan
    Zhao, Yanping
    Sanxing, Cao
    [J]. FIFTH INTERNATIONAL CONFERENCE ON FUZZY SYSTEMS AND KNOWLEDGE DISCOVERY, VOL 5, PROCEEDINGS, 2008, : 479 - +