首页> 外文会议>World multi-conference on systemics, cybernetics and informatics;WMSCI 2010 >Integrating Information Security Policy Management with Corporate Risk Management for Strategic Alignment
【24h】

Integrating Information Security Policy Management with Corporate Risk Management for Strategic Alignment

机译:将信息安全策略管理与公司风险管理相集成以实现战略调整

获取原文

摘要

Information security policy defines the governance and implementation strategy for information security in alignment with the corporate risk policy objectives and strategies. Research has shown that alignment between corporate functions may be enhanced when strategies are developed concurrently using the same development process as an integrative relationship is established. Utilizing the corporate risk management framework for security policy management establishes such an integrative relationship between information security and corporate risk management objectives and strategies. There is however limitation in the current literature on presenting a definitive approach that fully integrates security policy management with the corporate risk management framework. This paper presents an approach that adopts a conventional corporate risk management framework for security policy development and management to achieve alignment with the corporate risk policy objectives. A case example is examined to illustrate the alignment achieved in each process step with a security policy structure being derived in the process. It is shown that information security policy management outcomes become both integral drivers and major elements of the corporate-level risk management considerations. Further study should involve assessing the impact of the use of the proposed conceptual framework in enhancing alignment as presented in this paper.
机译:信息安全策略根据公司风险策略的目标和策略定义了信息安全的治理和实施策略。研究表明,当使用与集成关系相同的开发过程同时开发策略时,可以增强公司职能之间的一致性。利用公司风险管理框架进行安全策略管理,可以在信息安全与公司风险管理目标和策略之间建立这种整合关系。但是,在当前文献中,提出一种将安全策略管理与公司风险管理框架完全集成的确定性方法存在局限性。本文提出了一种采用常规公司风险管理框架进行安全策略开发和管理的方法,以实现与公司风险策略目标的一致。研究了一个案例示例,以说明在每个流程步骤中实现的一致性,并在流程中派生出安全策略结构。结果表明,信息安全策略管理结果既成为公司级风险管理考虑的不可或缺的驱动力,又成为其主要要素。进一步的研究应包括评估本文提出的概念框架对增强一致性的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号