• DocumentCode
    3423253
  • Title

    Information Security Governance control through comprehensive policy architectures

  • Author

    Von Solms, Rossouw ; Thomson, Kerry-Lynn ; Maninjwa, M.

  • Author_Institution
    Inst. of ICT Advancement, NMMU, Port Elizabeth, South Africa
  • fYear
    2011
  • fDate
    15-17 Aug. 2011
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Information Security Governance has become one of the key focus areas of strategic management due to its importance in the overall protection of the organization´s information assets. A properly implemented Information Security Governance framework should ideally facilitate the implementation of (directing), and compliance to (control), Strategic level management directives. These Strategic level management directives are normally interpreted, disseminated and implemented by means of a series of information security related policies. These policies should ideally be disseminated and implemented from the Strategic management level, through the Tactical level to the Operational level where eventual execution takes place. Control is normally exercised by capturing data at the lowest levels of execution and measuring compliance against the Operational level policies. Through statistical and summarized analyses of the Operational level data into higher levels of extraction, compliance at the Tactical and Strategic levels can be facilitated. This scenario of directing and controlling defines the basis of sound Information Security Governance. Unfortunately, information security policies are normally not disseminated onto the Operational level. As a result, proper controlling is difficult and therefore compliance measurement against all information security policies might be problematic. The objective of this paper is to argue towards a more complete information security policy architecture that will facilitate complete control, and therefore compliance, to ensure sound Information Security Governance.
  • Keywords
    security of data; statistical analysis; comprehensive policy architecture; information assets protection; information security governance control; statistical analysis; strategic level management directives; strategic levels; strategic management; tactical levels; Computer architecture; Documentation; Information security; Organizations; Process control; Standards organizations; Information security governance; direct-control; information security policies; policy architecture;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Security South Africa (ISSA), 2011
  • Conference_Location
    Johannesburg
  • Print_ISBN
    978-1-4577-1481-8
  • Type

    conf

  • DOI
    10.1109/ISSA.2011.6027522
  • Filename
    6027522