首页> 外文OA文献 >The enterprise information security policy as a strategic business policy within the corporate strategic plan (extended abstract)
【2h】

The enterprise information security policy as a strategic business policy within the corporate strategic plan (extended abstract)

机译:企业信息安全策略作为企业战略计划内的战略业务策略(扩展摘要)

摘要

Information security has been recognized as a core requirement for corporate governance that is expected to facilitate not only the management of risks, but also as a corporate enabler that supports and contributes to the sustainability of organizational operations. In implementing information security, the enterprise information security policy is the set of principles and strategies that guide the course of action for the security activities and may be represented as a brief statement that defines program goals and sets information security and risk requirements. The enterprise information security policy (alternatively referred to as security policy in this paper) that represents the meta-policy of information security is an element of corporate ICT governance and is derived from the strategic requirements for risk management and corporate governance. Consistent alignment between the security policy and the other corporate business policies and strategies has to be maintained if information security is to be implemented according to evolving business objectives. This alignment may be facilitated by managing security policy alongside other corporate business policies within the strategic management cycle. There are however limitations in current approaches for developing and managing the security policy to facilitate consistent strategic alignment. This paper proposes a conceptual framework for security policy management by presenting propositions to positively affect security policy alignment with business policies and prescribing a security policy management approach that expounds on the propositions.
机译:信息安全已被认为是公司治理的核心要求,它不仅有望促进风险管理,而且还将成为支持和促进组织运营可持续性的公司推动者。在实施信息安全中,企业信息安全策略是指导安全活动操作过程的一组原则和策略,可以表示为定义程序目标并设置信息安全和风险要求的简短声明。代表信息安全元策略的企业信息安全策略(在本文中也称为安全策略)是公司ICT治理的要素,并且源于风险管理和公司治理的战略要求。如果要根据不断发展的业务目标实施信息安全,则必须保持安全策略与其他公司业务策略和策略之间的一致性。通过在战略管理周期内将安全策略与其他公司业务策略一起管理,可以促进这种一致性。但是,当前用于开发和管理安全策略以促进一致的战略一致性的方法存在局限性。本文通过提出一些对安全策略与业务策略保持一致的建议,并提出一种针对该策略的安全策略管理方法,提出了一个安全策略管理的概念框架。

著录项

  • 作者

    Corpuz Maria;

  • 作者单位
  • 年度 2011
  • 总页数
  • 原文格式 PDF
  • 正文语种 {"code":"en","name":"English","id":9}
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号