首页> 外文会议>Americas Conference on Information Systems(AMCIS 2007); 20070810-12; Keystone,CO(US) >INFORMATION SECURITY GOVERNANCE ARRANGEMENTS: THE DEVIL IS IN THE DETAILS
【24h】

INFORMATION SECURITY GOVERNANCE ARRANGEMENTS: THE DEVIL IS IN THE DETAILS

机译:信息安全治理安排:细节中的秘密

获取原文
获取原文并翻译 | 示例

摘要

Information security governance includes the governance aspect, which sets the information security direction and strategy of an organization, and, the management aspect, which addresses how the strategy is implemented and managed. In this article, we focus on the management aspect of information security governance. Different organizational arrangements (i.e., governance arrangements) are possible to manage and implement the security strategy. One arrangement involves the creation of an information security department with a chief information security officer (CISO), or equivalent, to highlight the importance of security. Unfortunately, this may also create the impression that security is the responsibility of a special group and has little to do with the average employee. At the other extreme, no special security department is created. Instead, all employees have a significant role in maintaining information security in the organization. Such an arrangement may be more suited to implement guidelines, which suggest that security features are better built into business processes and software, rather than incorporated as an add-on layer. This arrangement diffuses the responsibility for security, and has the potential for diluting top management attention to security. In this research-in-progress paper, we propose a study to examine the effects of different governance arrangements.
机译:信息安全治理包括治理方面(用于设置组织的信息安全方向和策略)以及管理方面(用于解决如何实施和管理策略)。在本文中,我们重点介绍信息安全治理的管理方面。可以使用不同的组织安排(即治理安排)来管理和实施安全策略。一种安排涉及创建一个具有首席信息安全官(CISO)或同等职位的信息安全部门,以强调安全的重要性。不幸的是,这可能还会给人一种印象,即安全是一个特殊小组的责任,与普通员工无关。另一方面,没有创建专门的安全部门。相反,所有员工在维护组织中的信息安全方面都起着重要作用。这样的安排可能更适合于实施准则,该准则表明,安全功能可以更好地内置到业务流程和软件中,而不是作为附加层来合并。这种安排分散了对安全的责任,并有可能削弱高层管理人员对安全的关注。在这篇进行中的研究论文中,我们提出了一项研究,以研究不同治理安排的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号