The enterprise information security policy as a strategic business policy within the corporate strategic plan (extended abstract)


Autoria(s): Corpuz, Maria
Contribuinte(s)

Callaos, Nagib

Chu, Hsing-Wei

Data(s)

01/07/2011

Resumo

Information security has been recognized as a core requirement for corporate governance that is expected to facilitate not only the management of risks, but also as a corporate enabler that supports and contributes to the sustainability of organizational operations. In implementing information security, the enterprise information security policy is the set of principles and strategies that guide the course of action for the security activities and may be represented as a brief statement that defines program goals and sets information security and risk requirements. The enterprise information security policy (alternatively referred to as security policy in this paper) that represents the meta-policy of information security is an element of corporate ICT governance and is derived from the strategic requirements for risk management and corporate governance. Consistent alignment between the security policy and the other corporate business policies and strategies has to be maintained if information security is to be implemented according to evolving business objectives. This alignment may be facilitated by managing security policy alongside other corporate business policies within the strategic management cycle. There are however limitations in current approaches for developing and managing the security policy to facilitate consistent strategic alignment. This paper proposes a conceptual framework for security policy management by presenting propositions to positively affect security policy alignment with business policies and prescribing a security policy management approach that expounds on the propositions.

Formato

application/pdf

Identificador

http://eprints.qut.edu.au/51493/

Publicador

International Institute of Informatics and Systemics (IIIS)

Relação

http://eprints.qut.edu.au/51493/2/RA717ZB.pdf

http://www.iiis.org/CDs2011/CD2011SCI/RMCI_2011/PapersPdf/RA717ZB.pdf

Corpuz, Maria (2011) The enterprise information security policy as a strategic business policy within the corporate strategic plan (extended abstract). In Callaos, Nagib & Chu, Hsing-Wei (Eds.) Proceedings of the 15th World Multi-Conference on Systemics, Cybernetics and Informatics, International Institute of Informatics and Systemics (IIIS), Orlando, FL, USA, pp. 275-279.

Direitos

Copyright 2011 Please consult the author.

Fonte

Faculty of Science and Technology; Information Security Institute

Palavras-Chave #080303 Computer System Security #089999 Information and Computing Sciences not elsewhere classified #information security management #enterprise information security policy #strategic management
Tipo

Conference Paper