DocumentCode :
3642742
Title :
Information security governance and how to accomplish it
Author :
Mario Sajko;Nikola Hadjina;Ivan Sedinić
Author_Institution :
Poslovno savjetovanje i usluge - Segora, Varaž
fYear :
2011
fDate :
5/1/2011 12:00:00 AM
Firstpage :
1516
Lastpage :
1521
Abstract :
The risks and costs of information security, numerous external and internal requirements and obligations to customers, are the reason for the interest of security at the highest level in companies. A set of activities which describes the involvement of the management board, executive management, specialized committees, ad-hoc groups and security managers is referred as Security Governance. While the principles of information security governance are relatively defined, the universally accepted methodology for its introduction in business environment is missing. This raises the question whether there is a connection between other concepts of good practices in the field of security and IT management with Security Governance. Outlining the process of corporate security and its reference to other concepts of security and IT management, are the aims of this work.
Keywords :
"Information security","Process control","Monitoring","ISO standards","Organizations"
Publisher :
ieee
Conference_Titel :
MIPRO, 2011 Proceedings of the 34th International Convention
Print_ISBN :
978-1-4577-0996-8
Type :
conf
Filename :
5967301
Link To Document :
بازگشت