Information Security Governance Papers

Paper Title Information security management standards: Compliance, governance and risk management
The Abstract of The Paper Managing information security as opposed to the IT security is an area that is now eventually coming of age. For many years the focus has been mainly on IT security and with the implementation of such security left to the IT department and technical experts. Early in the 90s things started to change with the first draft of an information security management standard BS 7799 focusing in on security related to people, processes, information as well as IT. Since then there has been many developments taking us to where we are today with these early security management standards being transformed in international standards published by ISO/IEC. These standards are being used by hundreds of thousands of organisations using these standards worldwide. Based on the authors previously copyrighted writings, this article explores what these standards have got to offer organisations, what benefits are to be gained and how such standards have helped with compliance. In particular it focuses in on the insider threat as an example of one of the growing problems that organisations need to deal with and how these international standards are useful in helping to solve the insider threat problem.
Web Link http://www.sciencedirect.com/science?_ob=ArticleURL&_udi= B6VJC-4TRK0W8-1&_user=1723672&_coverDate=11%2F30%2F2008&_alid= 1240009675&_rdoc=13&_fmt=high&_orig=search&_cdi= 6091&_sort=r&_docanchor=&view=c&_ct=11395&_acct= C000052544&_version=1&_urlVersion=0&_userid= 1723672&md5=9ffd40dbf8d20e4850c305561a772c6c

Back To Information Security Governance Papers List

Database Sections