Improving information security compliance - A process-oriented approach for managing organizational change
نویسندگان
چکیده
Enterprises typically have to comply with many different legal, regulatory and internal requirements. Particularly in the context of information processing, there are dedicated regulations which demand the protection of the information infrastructure. From the authors’ point of view, organizational aspects are thereby one of the most critical improvement areas. However, the related organizational change process can be challenging in order to appropriately define and anchor adequate roles within the organization. To align the organization to the specific requirements of information security (IS), it is necessary to change the current organizational state into one that better supports the IS compliance performance. A process-oriented approach for managing the organizational change to improve information security compliance is presented in this contribution. The approach uses Business Aligned Information Security Management (BAISeM) and principles that have been derived from standards like ITIL, CObIT and ISO 27001. In order to illustrate the approach, the context of IT service continuity is selected as an example.
منابع مشابه
Exploring the Type of Relationship between Information Security Management and Organizational Culture (Case Study in TAM Iran Khodro Co.)
A culture conducive to information security practice is extremely important for organizations since information has to be critical assets in modern enterprises. Thus for understanding and improving the organizational behavior with regard to information security, enterprises may look into organizational culture and examine how it affects the effectiveness of implementing ISM. This study aims ...
متن کاملExploring the Type of Relationship between Information Security Management and Organizational Culture (Case Study in TAM Iran Khodro Co.)
A culture conducive to information security practice is extremely important for organizations since information has to be critical assets in modern enterprises. Thus for understanding and improving the organizational behavior with regard to information security, enterprises may look into organizational culture and examine how it affects the effectiveness of implementing ISM. This study aims ...
متن کاملاز پیاده سازی معماری سرویس گرا تا چابکی سازمان با رویکرد مدلسازی پویایی سیستم
SOA is type of architecture that used service to simplify integration activities and use the components for reusable. Companies to survive in the dynamic environment needed to strengthen their organizations through information systems and service-oriented architecture is a way for the integration and effectiveness of the use of information systems and achieve organizational agility. In this pap...
متن کاملImpact of Information Technology on Iran Distribution Company Performance in View of Organizational Infrastructures
The relationship between information technology investments and firm value as an area of inquiry has sustained interest among IS researchers over the past decade. Based on literature review of published work at corporate level productivity, researchers have developed three different approaches in assessing the correlation between IT implementation and productivity measures. Broadly speaking, th...
متن کاملInformation Security Governance: When Compliance Becomes More Important than Security
Current security governance is often based on a centralized decision making model and still uses an ineffective 20th century risk management approach to security. This approach is relatively simple to manage since it needs almost no security governance below the top enterprise level where most decisions are made. However, while there is a role for more corporate governance, new regulations, and...
متن کامل