An Open Reference Framework for Enterprise Information Security Risk Management Using the STOPE Scope and the Six-Sigma Process

نویسندگان

  • Mohamed Saad Saleh
  • Abdulkader Alfantookh
  • John Mellor
  • Saad Haj Bakry
چکیده

With the wide-spreading use of e-transactions in enterprises, information security risk management (ISRM) is becoming essential for establishing a safe environment for their activities. This paper is concerned with introducing a new and comprehensive ISRM framework that enables the effective establishment of the target safe environment. The framework has two structural dimensions; and two procedural dimensions. The structural dimensions include: ISRM "scope", and ISRM "assessment criteria"; while the procedural dimensions include: ISRM "process", and ISRM "assessment tools". The framework uses the comprehensive STOPE (Strategy, Technology, Organization, People, and Environment) view for the ISRM scope; while its assessment criteria is considered to be open to various standards. For the procedural dimensions, the framework uses the widely known six-sigma DAMIC (Define, Measure, Analyze, Improve, and Control) cycle for the ISRM process; and it considers the use of various assessment tools. It is hoped that the framework provides useful tools for future applications.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Mapping SAP-Six Sigma Resources to Agile Management Processes

Enterprise Resource Planning (ERP) has become the most strategic tool for an organization to employ. A leading ERP solution is SAP®. It has been employed by organizations to enable them to collaborate on different projects and to integrate all aspects of operations. Just as organizations have adopted ERP solutions, they employed quality initiatives that are designed to help organizations ma...

متن کامل

Reputation Risk Management in the Framework of Enterprise Risk Management: Evidences from an Active Financial Institution in the Capital Market of Iran

Reputation risk as one of the most important risks in any competitive industry and market should be considered before all the risks of the enterprise which also affects other risks. This research aims to review and manage reputation risk in the framework of enterprise risk management. Considering the importance of the subject and lack of available studies in this field, the innovation of presen...

متن کامل

A Proposed Model for Assessing the Determinants of Enterprise Resource Planning Adoption and Satisfaction

 The complex information systems such as enterprise resource planning (ERP) systems are essential for organizations to make them competitive. However, the success of ERP system projects is a difficult process as it involves different types of end user assessment. The main objective of the present study is to find the key determinants that open the door to employee satisfaction and adoption of E...

متن کامل

Knowledge Management: An Instrument for the Development of the Knowledge Society

Building a knowledge-based society is widely recognized as leading to human, social and economic benefits. This paper explores the issue of using knowledge management as an instrument for the development and sustainability of this knowledge society. The paper attempts to achieve its purpose through four main integrated steps: providing a brief review of knowledge management and the knowledge so...

متن کامل

Providing an Enterprise Architecture Framework Model for Laboratory Information Management Systems by Service Oriented Approach

Background and Aim: Laboratories are one of the most important scientific and research centers. Laboratory information management systems provide a platform for recording the information and collaborating between researchers. The main purpose of this study was suggesting an organizational architecture model of laboratory information management systems.  Materials and Methods: This study was a ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2008