Aligning the information security policy with the strategic information systems plan

被引:61
|
作者
Doherty, NF [1 ]
Fulford, H [1 ]
机构
[1] Univ Loughborough, Sch Business, Loughborough LE11 3TU, Leics, England
关键词
strategic information systems planning; information security policy; security breaches; alignment; information security management; information security policy components;
D O I
10.1016/j.cose.2005.09.009
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Two of the most important documents for ensuring the effective deployment of information systems and technologies within the modem business enterprise are the strategic information systems plan (SISP) and the information security policy. The strategic information systems plan ensures that new systems and technologies are deployed in a way that will support an Organisation's strategic goals whilst the information security policy provides a framework to ensure that systems are developed and operated in a secure manner. To date, the literature with regard to the formulation of the information security policy has tended to ignore its important relationship with the strategic information systems plan, and vice versa. In this paper we argue that these two important policy documents should be explicitly and carefully aligned to ensure that the outcomes of strategically important information system initiatives are not compromised by problems with their security. (C) 2005 Elsevier Ltd. All rights reserved.
引用
收藏
页码:55 / 63
页数:9
相关论文
共 50 条
  • [1] The Enterprise Information Security Policy as a Strategic Business Policy within the Corporate Strategic Plan
    Corpuz, Maria Soto
    WMSCI 2011: 15TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL III, 2011, : 275 - 279
  • [2] Integrating Strategic Information Systems Planning into Nigerian Security Agencies
    Umar, Nana Aisha
    Awwalu, Jamilu
    2019 15TH INTERNATIONAL CONFERENCE ON ELECTRONICS, COMPUTER AND COMPUTATION (ICECCO), 2019,
  • [3] A baseline security policy for distributed healthcare information systems
    Gritzalis, D
    COMPUTERS & SECURITY, 1997, 16 (08) : 709 - 719
  • [4] Impact of Knowledge Acquisition to Strategic Information Systems Plan Implementation in Ethiopia
    Mkhize, Peter
    PROCEEDINGS OF THE 15TH EUROPEAN CONFERENCE ON KNOWLEDGE MANAGEMENT (ECKM 2014), VOLS 1-3, 2014, : 659 - 666
  • [5] Issues and Trends in Information Security Policy Compliance
    Bhaharin, Surayahani Hasnul
    Mokhtar, Umi Asma
    Sulaiman, Rossilawati
    Yusof, Maryati Mohd
    2019 6TH INTERNATIONAL CONFERENCE ON RESEARCH AND INNOVATION IN INFORMATION SYSTEMS: EMPOWERING DIGITAL INNOVATION (ICRIIS 2019), 2019,
  • [6] Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness
    Bulgurcu B.
    Cavusoglu H.
    Benbasat I.
    MIS Quarterly: Management Information Systems, 2010, 34 (SPEC. ISSUE 3): : 523 - 548
  • [7] INFORMATION SECURITY POLICY COMPLIANCE: AN EMPIRICAL STUDY OF RATIONALITY-BASED BELIEFS AND INFORMATION SECURITY AWARENESS
    Bulgurcu, Burcu
    Cavusoglu, Hasan
    Benbasat, Izak
    MIS QUARTERLY, 2010, 34 (03) : 523 - 548
  • [8] Information security policy -: what do international information security standards say?
    Höne, K
    Eloff, JHP
    COMPUTERS & SECURITY, 2002, 21 (05) : 402 - 409
  • [9] Performance effects of aligning service innovation and the strategic use of information technology
    Hui-Ling Huang
    Service Business, 2014, 8 : 171 - 195
  • [10] Performance effects of aligning service innovation and the strategic use of information technology
    Huang, Hui-Ling
    SERVICE BUSINESS, 2014, 8 (02) : 171 - 195