Integrating Information Security Policy Management with Corporate Risk Management for Strategic Alignment

被引:0
|
作者
Corpuz, Maria Soto [1 ]
Barnes, Paul [1 ]
机构
[1] Queensland Univ Technol, Informat Secur Inst, Brisbane, Qld 4000, Australia
来源
WMSCI 2010: 14TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL III | 2010年
关键词
Information security; security management; security policy; risk management; risk policy; risk analysis;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Information security policy defines the governance and implementation strategy for information security in alignment with the corporate risk policy objectives and strategies. Research has shown that alignment between corporate functions may be enhanced when strategies are developed concurrently using the same development process as an integrative relationship is established. Utilizing the corporate risk management framework for security policy management establishes such an integrative relationship between information security and corporate risk management objectives and strategies. There is however limitation in the current literature on presenting a definitive approach that fully integrates security policy management with the corporate risk management framework. This paper presents an approach that adopts a conventional corporate risk management framework for security policy development and management to achieve alignment with the corporate risk policy objectives. A case example is examined to illustrate the alignment achieved in each process step with a security policy structure being derived in the process. It is shown that information security policy management outcomes become both integral drivers and major elements of the corporate-level risk management considerations. Further study should involve assessing the impact of the use of the proposed conceptual framework in enhancing alignment as presented in this paper.
引用
收藏
页码:337 / 342
页数:6
相关论文
共 50 条
  • [1] Survey on Information System Security Risk Management alignment
    Abbass, Wissam
    Baina, Amine
    Bellafkih, Mostafa
    2016 INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY FOR ORGANIZATIONS DEVELOPMENT (IT4OD), 2016,
  • [2] Integrating information quality dimensions into information security risk management (ISRM)
    Shamala, Palaniappan
    Ahmad, Rabiah
    Zolait, Ali
    Sedek, Muliati
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2017, 36 : 1 - 10
  • [3] Making Risk Management Strategic: Integrating Enterprise Risk Management with Strategic Planning
    Sax, Johanna
    Andersen, Torben Juul
    EUROPEAN MANAGEMENT REVIEW, 2019, 16 (03) : 719 - 740
  • [4] Strategic value alignment for information security management: a critical success factor analysis
    Tu, Cindy Zhiling
    Yuan, Yufei
    Archer, Norm
    Connelly, Catherine E.
    INFORMATION AND COMPUTER SECURITY, 2018, 26 (02) : 150 - 170
  • [5] The Enterprise Information Security Policy as a Strategic Business Policy within the Corporate Strategic Plan
    Corpuz, Maria Soto
    WMSCI 2011: 15TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL III, 2011, : 275 - 279
  • [6] A Corporate Employee as a Subject of Corporate Information Security Management
    L. V. Astakhova
    Scientific and Technical Information Processing, 2020, 47 : 113 - 118
  • [7] A Corporate Employee as a Subject of Corporate Information Security Management
    Astakhova, L. V.
    SCIENTIFIC AND TECHNICAL INFORMATION PROCESSING, 2020, 47 (02) : 113 - 118
  • [8] INFORMATION ASPECT OF CORPORATE GOVERNANCE AND STRATEGIC MANAGEMENT
    Isaev, D. V.
    TERRA ECONOMICUS, 2008, 6 (03): : 114 - 119
  • [9] Security Governance, Management, and Strategic Alignment via Capabilities
    Jackson, George W., Jr.
    Rahman, Shawon S. M.
    PROCEEDINGS 2017 INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND COMPUTATIONAL INTELLIGENCE (CSCI), 2017, : 44 - 49
  • [10] Strategic risk management in building security
    Rohacs, Viktor J.
    PROGRESS IN SAFETY SCIENCE AND TECHNOLOGY, VOL 6, PTS A AND B, 2006, 6 : 2517 - 2523