• DocumentCode
    130427
  • Title

    A comparison between business process management and information security management

  • Author

    Wangen, Gaute ; Snekkenes, Einar Arthur

  • Author_Institution
    Norwegian Inf. Security Lab., Gjovik Univ. Coll., Gjovik, Norway
  • fYear
    2014
  • fDate
    7-10 Sept. 2014
  • Firstpage
    901
  • Lastpage
    910
  • Abstract
    Information Security Standards such as NIST SP 800-39 and ISO/IEC 27005:2011 are turning their scope towards business process security. And rightly so, as introducing an information security control into a business-processing environment is likely to affect business process flow, while redesigning a business process will most certainly have security implications. Hence, in this paper, we investigate the similarities and differences between Business Process Management (BPM) and Information Security Management (ISM), and explore the obstacles and opportunities for integrating the two concepts. We compare three levels of abstraction common for both approaches; top-level implementation strategies, organizational risk views & associated tasks, and domains. With some minor differences, the comparisons shows that there is a strong similarity in the implementation strategies, organizational views and tasks of both methods. The domain comparison shows that ISM maps to the BPM domains; however, some of the BPM domains have only limited support in ISM.
  • Keywords
    ISO standards; business data processing; security of data; BPM; ISM; ISO/IEC 27005:2011 standard; NIST SP 800-39 standard; business process flow; business process management; business process redesign; business process security; business processing environment; information security control; information security management; information security standards; IEC standards; ISO standards; Information security; Organizations; Standards organizations; BPM Methodology Framework; Business Process Management; ISO/IEC 27001; ISO/IEC 27002; ISO/IEC 27005; Information Security; Information Security Risk Management; NIST SP 800-39;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Science and Information Systems (FedCSIS), 2014 Federated Conference on
  • Conference_Location
    Warsaw
  • Type

    conf

  • DOI
    10.15439/2014F77
  • Filename
    6933111