Governance Practices and Critical Success factors suitable for Business Information Security

被引:5
作者
Bobbert, Yuri [1 ]
Mulder, Hans [2 ]
机构
[1] Univ Antwerp, LOI Univ Appl Sci, Antwerp, Belgium
[2] Univ Antwerp, Antwerp Management Sch, Antwerp, Belgium
来源
2015 INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND COMMUNICATION NETWORKS (CICN) | 2015年
关键词
Business Information Security Governance; Corporate Governance; Information Security Management; Risk Management; Security Governance Principles;
D O I
10.1109/CICN.2015.216
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Information Security (IS) is increasingly becoming an integrated business practice instead of just IT. Security breaches are a challenge to organizations. They run the risk of losing revenue, trust and reputation and in extreme cases they might even go under. IS literature emphasizes the necessity to govern Information Security at the level of the Board of Directors (BoD) and to execute (i.e. plan, build, run and monitor) it at management level. This paper describes explorative research into IS-relevant Governance and Executive management practices. Answering the main research question: "Which practices at the level of Governance are relevant for Business Information Security Maturity" The initial phase of this research consists of a review of academic and practice-oriented literature on these relevant practices. This list of practices is then examined and validated through expert panel research using a Group Support System (GSS). The paper ultimately identifies a list of 22 core principles. This list can function as frame of reference for Boards of Directors and Management Teams in order to increase their level of Business Information Security (BIS) Maturity.
引用
收藏
页码:1097 / 1104
页数:8
相关论文
共 58 条
[1]  
AberdeenGroup, 2005, BEST PRACT SEC GOV
[2]  
[Anonymous], 2005, INF RISKS WHOS BUS A
[3]  
[Anonymous], 2004, OECD PRINC CORP GOV
[4]  
[Anonymous], 2004, ENTERPRISE RISK MANA
[5]  
[Anonymous], CACG GUID PRINC CORP
[6]  
[Anonymous], 2011, EMBRACING ENTERPRISE
[7]  
[Anonymous], 2009, FAILURE RISK MANAGEM
[8]  
[Anonymous], 2010, UK CORP GOV COD
[9]  
[Anonymous], 2002, KING REP CORP GOV S
[10]  
Asch S.E., 1951, ORG INFLUENCE PROCES, P295