A Framework for Information Security Governance and Management

被引:18
|
作者
Carcary, Marian [1 ]
Renaud, Karen [2 ]
McLaughlin, Stephen [3 ,4 ]
O'Brien, Conor [1 ]
机构
[1] Maynooth Univ, Innovat Value Inst, Maynooth, Kildare, Ireland
[2] Univ Glasgow, Glasgow G12 8QQ, Lanark, Scotland
[3] Maynooth Univ, R&D, Innovat Value Inst, Maynooth, Kildare, Ireland
[4] Maynooth Univ, IT Competence Ctr, Maynooth, Kildare, Ireland
关键词
capability maturity; information security governance; information security management; IT-CMF;
D O I
10.1109/MITP.2016.27
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The capability maturity framework presented helps organizations assess their maturity state and identify problem areas. It addresses the technical, process, and human aspects of information security and provides guidelines for implementing information security governance and management processes.
引用
下载
收藏
页码:22 / 30
页数:9
相关论文
共 50 条
  • [1] Information security governance framework
    Faculty of Informatics, Kogakuin University, Japan
    不详
    不详
    不详
    不详
    不详
    Proc ACM Conf Computer Commun Secur, (1-5):
  • [2] An information security governance framework
    Da Veiga, A.
    Eloff, J. H. P.
    INFORMATION SYSTEMS MANAGEMENT, 2007, 24 (04) : 361 - 372
  • [3] A framework for the governance of information security
    Posthumus, S
    von Solms, R
    COMPUTERS & SECURITY, 2004, 23 (08) : 638 - 646
  • [4] Towards a Framework for Strategic Security Context in Information Security Governance
    Maynard, Sean B.
    Tan, Terrence
    Ahmad, Atif
    Ruighaver, Tobias
    PACIFIC ASIA JOURNAL OF THE ASSOCIATION FOR INFORMATION SYSTEMS, 2018, 10 (04): : 65 - 88
  • [5] A FRAMEWORK FOR INFORMATION SECURITY MANAGEMENT
    Angheluta, Dragos-Ionut
    Lupu, Luminita-Mihaela
    FROM MANAGEMENT OF CRISIS TO MANAGEMENT IN A TIME OF CRISIS, 2016, : 2 - 16
  • [6] A framework for the management of information security
    Leiwo, J
    Zheng, YL
    INFORMATION SECURITY, 1998, 1396 : 232 - 245
  • [7] A framework for the governance of information security: Can it be used in an organization
    Antoniou, George S.
    IEEE SOUTHEASTCON 2018, 2018,
  • [8] Towards a holistic Information Security Governance Framework for SOA
    Coetzee, Marijke
    2012 SEVENTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES), 2012, : 155 - 160
  • [9] Developing and Validating a Healthcare Information Security Governance Framework
    Mahncke, Rachel
    Williams, Patricia
    ELECTRONIC JOURNAL OF HEALTH INFORMATICS, 2014, 8 (02):
  • [10] Information security governance: A challenge for senior management
    von Solms, R
    Innovations Through Information Technology, Vols 1 and 2, 2004, : 1130 - 1131