• DocumentCode
    884805
  • Title

    Maximizing business information security´s educational value

  • Author

    Grimaila, Michael Russell

  • Author_Institution
    Texas A&M Univ., TX, USA
  • Volume
    2
  • Issue
    1
  • fYear
    2004
  • Firstpage
    56
  • Lastpage
    60
  • Abstract
    A business information security course´s goals and objectives are quite different from most traditional security courses, which focus on designing and developing new security technologies. Business information security primarily concerns the strategic, tactical, and operational management issues surrounding the planning, analysis, design, implementation, and maintenance of an organization´s information security program. Core issues include asset valuation, auditing, business continuity planning, disaster recovery planning, ethics, organizational communication, policy development, project planning, risk management, security awareness education and training, and various legal issues such as liability and regulatory compliance. Because businesses can´t afford to mitigate all security risks, students must learn methods to identify and justify the optimal amount of expenditures to ensure that their information assets are sufficiently protected. Students should also understand the technical components of security so they can appreciate the problems experienced by the people they manage. This paper describes my experiences in developing a business information security course that provides students the knowledge arid experience to succeed in today´s competitive information-intensive corporate environment.
  • Keywords
    educational courses; ethical aspects; security of data; business continuity planning; business information security; business information security course; disaster recovery planning; ethics; information-intensive corporate environment; operational management; strategic management; tactical management; Business continuity; Continuing education; Cost accounting; Disaster management; Ethics; Information analysis; Information security; Professional communication; Risk management; Strategic planning;
  • fLanguage
    English
  • Journal_Title
    Security & Privacy, IEEE
  • Publisher
    ieee
  • ISSN
    1540-7993
  • Type

    jour

  • DOI
    10.1109/MSECP.2004.1264855
  • Filename
    1264855