Integration of COBIT, Balanced Scorecard and SSE- CMM as a strategic Information Secur ity Management (ISM) framework
نویسندگان
چکیده
Abstr act The purpose of this study is to explore the integrated use of Control Objectives for Information Technology (COBIT) and Balanced Scorecard (BSC) frameworks for strategic information security management (ISM). The goal is to investigate the strengths, weaknesses, implementation techniques, and potential benefits of such an integrated framework. This integration is achieved by “bridging” the gaps or mitigating the weaknesses that are recognized within one framework, using the methodology prescribed by the second framework. Thus, integration of COBIT and BSC can provide a more comprehensive mechanism for strategic information security management (ISM) – one that is fully aligned with business, IT and information security strategies. The use of Systems Security Engineering Capability Maturity Model (SSE-CMM) as a tool for performance measurement and evaluation can ensure the adoption of a continuous improvement approach for successful sustainability of this comprehensive framework. There are some instances of similar studies conducted previously: • metrics based security assessment [1] using ISO 27001 and SSE-CMM • mapping of processes for effective integration of COBIT and SEI-CMM [2] • mapping of COBIT with ITIL and ISO 27002 [3] for effective management and alignment of IT with business The factor that differentiates this research study from the previous ones is that none of the previous studies integrated BSC, COBIT and SSE-CMM, to formulate a comprehensive framework for strategic ISM that is aligned with business, IT and information security strategies. Therefore, a valid opportunity to conduct this research study exists.
منابع مشابه
IT Security Governance: A Framework based on ISO 38500
ISO 38500 is an international standard for IT governance. The guidelines of ISO 38500 can also be applied at the IT security functional level in order to guide the governance of IT security. This paper proposes the use of a strategic information security management (ISM) framework to implement guidelines of ISO 38500. This approach provides several strategic advantages to the organization by 1)...
متن کاملDevelopment of using balance scorecard in universities for having better performance: a fuzzy DEMATEL-Shapley value goal programming approach
Universities have a magnificent role in the sustainable development of their country and international scientific production of their country. Purpose of this paper is expansion of using balance scorecard in universities In order to improve performance of universities in learning and educating. The Balanced Scorecard (BSC) is an extensively adopted performance management framework in a lot of o...
متن کاملInvestigating causal linkages and strategic mapping in the balanced scorecard: A case study approach in the banking industry sector
One of the main challenges of strategic management is implementing the strategies. Designing the strategy map in Balanced Scorecard framework to determine the causality between strategic objectives is one of the most important issues in implementing the strategies. In designing the strategy map with intuition and judgment, the link between strategic objectives is not clear and it is not obvious...
متن کاملDevelopment of using balance scorecard in universities for having better performance: a fuzzy DEMATEL-Shapley value goal programming approach
Universities have a magnificent role in the sustainable development of their country and international scientific production of their country. Purpose of this paper is expansion of using balance scorecard in universities In order to improve performance of universities in learning and educating. The Balanced Scorecard (BSC) is an extensively adopted performance management framework in a lot of o...
متن کاملDetermining the Key Indicators affecting Electronic Customer Relationship Management (e-CRM) Using an integration of balanced scorecard and fuzzy screening techniques (Case Study: Companies Covered by Parsian Data-Processors Group)
Nowadays, increasing competition among companies and the huge cost of attracting new customers has led to companies seeking to retain existing customers rather than looking to attract new customers. These factors together have led to the emergence of customer relationship management. Thanks to the development of information and communication technology, especially the Internet, the use of custo...
متن کامل