An Integrated Framework for Information Security Management

被引:0
|
作者
Ma, Qingxiong [1 ]
Schmidt, Mark B. [2 ]
Pearson, J. Michael [3 ]
机构
[1] Univ Cent Missouri, Harmon Coll Business Adm, Warrensburg, MO 64093 USA
[2] St Cloud State Univ, GR Herberger Coll Business, St Cloud, MN 56301 USA
[3] Southern Illinois Univ, Coll Business Adm, Carbondale, IL 62901 USA
来源
REVIEW OF BUSINESS | 2009年 / 30卷 / 01期
关键词
D O I
暂无
中图分类号
F [经济];
学科分类号
02 ;
摘要
Today information assets face more potential security breaches than at any time in history. To help mitigate the effect of the threats, information security management (ISM) is a very important part of a successful organization's strategic plan. Due to a significant increase in the number of threats over the past decade, organizations need to be proactive to protect their information assets. Unfortunately, there is a lack of experts qualified to address the area of IT security. We propose an integrated framework for ISM, in which it is conceptualized as a continuous decision-making process. The rationale of this framework is based on four guiding principles. 1) Have goal in mind. 2) Align security goals with business strategy. 3) ISM is a multivariate system. 4) ISM is a dynamic process. ISM is more about the operating procedures and processes in which crucial components such as organizational infrastructure, human factors and information security practices are all involved. Key components of the ISM framework include the following steps. 1. Assess the organizational environment. 2. Establish information security objectives. 3. Analyze information security requirements. 4. Develop information security controls. 5. Train/evaluate information security controls. Researchers find that despite the seriousness of the nature and scope of the security threats posed by the environment, many organizations are under-prepared or completely unprepared to mitigate the threatsystems. Further, there appears to be a lack of consensus as to how an organization should implement an information security policy, what information security objectives should be established, or how to react when the information systems are threatened. The framework described herein could be utilized in an effort to effectively implement a holistic and successful ISM plan.
引用
收藏
页码:58 / 69
页数:12
相关论文
共 50 条
  • [1] An integrated system for information security management with the unified framework
    Yang, Tsung-Han
    Ku, Cheng-Yuan
    Liu, Man-Nung
    [J]. JOURNAL OF RISK RESEARCH, 2016, 19 (01) : 21 - 41
  • [2] A FRAMEWORK FOR INFORMATION SECURITY MANAGEMENT
    Angheluta, Dragos-Ionut
    Lupu, Luminita-Mihaela
    [J]. FROM MANAGEMENT OF CRISIS TO MANAGEMENT IN A TIME OF CRISIS, 2016, : 2 - 16
  • [3] A framework for the management of information security
    Leiwo, J
    Zheng, YL
    [J]. INFORMATION SECURITY, 1998, 1396 : 232 - 245
  • [4] A Framework of Information Security Integrated with Human Factors
    Al-Darwish, Ahmed, I
    Choe, Pilsung
    [J]. HCI FOR CYBERSECURITY, PRIVACY AND TRUST, 2019, 11594 : 217 - 229
  • [5] A conceptual framework for information security management
    Finne, T
    [J]. COMPUTERS & SECURITY, 1998, 17 (04) : 303 - 307
  • [6] A framework for the management of information security risks
    Jones, A.
    [J]. BT TECHNOLOGY JOURNAL, 2007, 25 (01) : 30 - 36
  • [7] A Framework for Information Security Governance and Management
    Carcary, Marian
    Renaud, Karen
    McLaughlin, Stephen
    O'Brien, Conor
    [J]. IT PROFESSIONAL, 2016, 18 (02) : 22 - 30
  • [8] A process framework for information security management
    Haufe, Knut
    Colomo-Palacios, Ricardo
    Dzombeta, Srdan
    Brandis, Knud
    Stantchev, Vladimir
    [J]. IJISPM-INTERNATIONAL JOURNAL OF INFORMATION SYSTEMS AND PROJECT MANAGEMENT, 2016, 4 (04): : 27 - 47
  • [9] An integrated security framework for XML based management
    Cridlig, V
    State, R
    Festor, O
    [J]. INTEGRATED NETWORK MANAGEMENT IX: MANAGING NEW NETWORKED WORLDS, 2005, : 587 - 600
  • [10] Integrated framework for information security investment and cyber insurance
    Wang, Shaun S.
    [J]. PACIFIC-BASIN FINANCE JOURNAL, 2019, 57