Abstract
Today information assets face more potential security breaches than at any time in history. To help mitigate the effect of the threats, information security management (ISM) is a very important part of a successful organization's strategic plan. Due to a significant increase in the number of threats over the past decade, organizations need to be proactive to protect their information assets. Unfortunately, there is a lack of experts qualified to address the area of IT security. We propose an integrated framework for ISM, in which it is conceptualized as a continuous decision-making process. The rationale of this framework is based on four guiding principles. 1) Have goal in mind. 2) Align security goals with business strategy. 3) ISM is a multivariate system. 4) ISM is a dynamic process. ISM is more about the operating procedures and processes in which crucial components such as organizational infrastructure, human factors and information security practices are all involved. Key compo
Cite
CITATION STYLE
Ma, Q., Schmidt, M., & Pearson, J. (2009). An Integrated Framework for Information Security Management. Review of Business, 30, 58–69. Retrieved from http://ezproxy.library.capella.edu/login?url=http://search.ebscohost.com.library.capella.edu/login.aspx?direct=true&db=bth&AN=47777757&site=ehost-live&scope=site
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.