Aligning the information security policy with the strategic information systems plan

نویسندگان

  • Neil F. Doherty
  • Heather Fulford
چکیده

Two of the most important documents for ensuring the effective deployment of information systems and technologies within the modern business enterprise are the strategic information systems plan [SISP] and the information security policy. The strategic information systems plan ensures that new systems and technologies are deployed in a way that will support an organisation’s strategic goals whilst the information security policy provides a framework to ensure that systems are developed and operated in a secure manner. To date, the literature with regard to the formulation of the information security policy has tended to ignore its important relationship with the strategic information systems plan, and vice versa. In this paper we argue that these two important policy documents should be explicitly and carefully aligned to ensure that the outcomes of strategically important information system initiatives are not compromised by problems with their security.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

امنیت اطلاعات سامانه های تحت وب نهاد کتابخانه های عمومی کشور

Purpose: This paper aims to evaluate the security of web-based information systems of Iran Public Libraries Foundation (IPLF). Methodology: Survey method was used as a method for implementation. The tool for data collection was a questionnaire, based on the standard ISO/IEC 27002, that has the eleven indicators and 79 sub-criteria, which examines security of web-based information systems of IP...

متن کامل

Critical Success Factors in implementing information security governance (Case study: Iranian Central Oil Fields Company)

The oil industry, as one of the main industries of the country, has always faced cyber attacks and security threats. Therefore, the integration of information security in corporate governance is essential and a governance challenge. The integration of information security and corporate governance is called information security governance. In this research, we identified "critical success factor...

متن کامل

برنامه‌ریزی استراتژیک سیستم‌ها و فناوری‌های اطلاعاتی: ضرورتی بنیادین در برنامه چهارم توسعه

Information Systems/ Information Technology (IS/IT) signifies an organization's use of computer systems for project completion and goal realization. Strategic planning has, for long, empowered the organizations to fully utilize the information systems and technologies at their disposal. Research findings, however, indicate how complex and fraught with setbacks this kind of planning can be. With...

متن کامل

The Enterprise Information Security Policy as a Strategic Business Policy within the Corporate Strategic Plan

Information security has been recognized as a core requirement for corporate governance that is expected to facilitate not only the management of risks [1][2], but also as a corporate enabler that supports and contributes to the sustainability of organizational operations [3]. In implementing information security, the enterprise information security policy is the set of principles and strategie...

متن کامل

Exploring the infrastructures for establishment of electronic municipality (e-municipality) in metropolis city of Tabriz

The purpose of this study is to explore infrastructures for establishment of electronic municipality in metropolis city of Tabriz. Thisis a descriptive survey and it is an applied one in terms of goal .Total sample consisted of total number of 120 employees in Statistics and Information Technology Department of municipality as well as those working in related sections to information technolog...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • Computers & Security

دوره 25  شماره 

صفحات  -

تاریخ انتشار 2006