Alignment for Information Security Professionals, ICT Security Auditors and Regulatory Officials in Implementing Information Security in South Africa

被引:0
|
作者
Basani, Mandla [1 ]
Loock, Marianne [1 ]
Kritzinger, Elmarie [1 ]
机构
[1] Univ S Africa, ZA-0001 Pretoria, South Africa
关键词
Information Security Professionals; ICT Security Auditors; Regulatory Officials; Framework;
D O I
暂无
中图分类号
F [经济];
学科分类号
02 ;
摘要
Information security is, through IT governance, part of corporate governance. Corporate governance requires that there be structures and processes in place with appropriate checks and balances that enable the directors to discharge their responsibilities. To support this principle means that there must be proper checks and balances for all information security implementations. Achieving this partly requires the involvement of three key role players namely: information security professionals, ICT security auditors and regulatory officials. These three role players must ensure that the information security controls are implemented, properly checked and independently evaluated against the organisation's strategic objectives and the regulatory requirements. In order to ensure effectiveness, the three role players must be aligned in the implementation and evaluation of information security controls. This alignment must be based on a common framework understood and accepted by all three role players. The article presents a South African Information Security Alignment (SAISA) framework to address this.
引用
收藏
页码:1044 / 1053
页数:10
相关论文
共 50 条
  • [1] Information security education in South Africa
    Futcher L.
    Schroder C.
    Von Solms R.
    Information Management and Computer Security, 2010, 18 (05): : 366 - 374
  • [2] IS professionals' information security behaviors in Chinese IT organizations for information security protection
    Ma, Xiaofen
    INFORMATION PROCESSING & MANAGEMENT, 2022, 59 (01)
  • [3] INFORMATION SECURITY SOUTH AFRICA (ISSA) 2017
    Flowerday, Stephen V.
    SAIEE AFRICA RESEARCH JOURNAL, 2018, 109 (02): : 84 - 84
  • [4] INFORMATION SECURITY SOUTH AFRICA (ISSA) 2014
    von Solms, Rossouw
    SAIEE AFRICA RESEARCH JOURNAL, 2015, 106 (02): : 44 - 44
  • [5] INFORMATION SECURITY SOUTH AFRICA (ISSA) 2015
    Flowerday, Stephen V.
    SAIEE AFRICA RESEARCH JOURNAL, 2016, 107 (02): : 52 - 52
  • [6] INFORMATION SECURITY SOUTH AFRICA (ISSA) 2018
    Ophoff, Jacques
    SAIEE AFRICA RESEARCH JOURNAL, 2019, 110 (02): : 52 - 52
  • [7] Information Security on Portuguese Statutory Auditors firms
    Lima, Isadora
    Pedrosa, Isabel
    Rito, Sonia
    2020 15TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI'2020), 2020,
  • [8] Measuring organizational information security awareness in South Africa
    Kritzinger, Elmarie
    Da Veiga, Adele
    van Staden, Wynand
    INFORMATION SECURITY JOURNAL, 2023, 32 (02): : 120 - 133
  • [9] Firm objectives, IT alignment, and information security
    Anderson, E. E.
    IBM JOURNAL OF RESEARCH AND DEVELOPMENT, 2010, 54 (03)
  • [10] The State of e-Government Security in South Africa: Analysing the National Information Security Policy
    Ngoqo, Bukelwa
    Njenga, Kennedy
    E-INFRASTRUCTURE AND E-SERVICES FOR DEVELOPING COUNTRIES (AFRICOMM 2017), 2018, 250 : 29 - 46