Integrating information security policy management with corporate risk management for strategic alignment


Autoria(s): Corpuz, Maria; Barnes, Paul H.
Data(s)

2010

Resumo

Information security policy defines the governance and implementation strategy for information security in alignment with the corporate risk policy objectives and strategies. Research has established that alignment between corporate concerns may be enhanced when strategies are developed concurrently using the same development process as an integrative relationship is established. Utilizing the corporate risk management framework for security policy management establishes such an integrative relationship between information security and corporate risk management objectives and strategies. There is however limitation in the current literature on presenting a definitive approach that fully integrates security policy management with the corporate risk management framework. This paper presents an approach that adopts a conventional corporate risk management framework for security policy development and management to achieve alignment with the corporate risk policy. A case example is examined to illustrate the alignment achieved in each process step with a security policy structure being consequently derived in the process. It is shown that information security policy management outcomes become both integral drivers and major elements of the corporate-level risk management considerations. Further study should involve assessing the impact of the use of the proposed framework in enhancing alignment as perceived in this paper.

Formato

application/pdf

Identificador

http://eprints.qut.edu.au/38217/

Relação

http://eprints.qut.edu.au/38217/1/c38217.pdf

http://www.certh.gr/9AF6CDF6.en.aspx

Corpuz, Maria & Barnes, Paul H. (2010) Integrating information security policy management with corporate risk management for strategic alignment. In Proceedings of the 14th World Multi-Conference on Systemics, Cybernetics and Informatics (WMSCI 2010), Orlando, Florida.

Direitos

Copyright 2010 [please consult the authors]

Fonte

QUT Business School; Information Security Institute; School of Management

Palavras-Chave #150302 Business Information Systems #Information Security #Security Management #Security Policy #Risk Management #Risk Policy
Tipo

Conference Paper