Balancing IT Security Management Model Trade-Offs

نویسندگان

  • Kirstie Hawkey
  • Kasia Muldner
چکیده

IT security professionals' effectiveness in an organization is influenced not only by how usable their security management tools are but also by how well the organization's security management model (SMM) fits. Finding the right SMM is critical but can be challenging — trade-offs are inherent to each approach but their implications aren't always clear. The authors present a case study of one academic institution that created a centralized security team but disbanded it in favor of a more distributed approach three years later. They contrast these experiences with expectations from industry standards. T he critical challenge of protecting an organization's assets from Internet attacks is multidimen-sional. Success depends not only on the usability of security management tools but also on the overall effectiveness of processes for IT security management. Many factors influence these processes , including an organization's level of commitment to security 1 and the type of security management model (SMM) that shapes the security team's structure , dynamics, and responsibilities. What's more, the recent push toward accountable IT governance has highlighted the need for formalized IT security management structures that can meet legislated requirements. For example, the Sarbanes-Oxley Act of 2002 mandates accountable use of IT controls in publicly traded US companies. However, legislation and guidelines for IT governance (such as the IT Governance Institute's " COBIT: Control Objectives of Information and Related Technology " ; www.isaca.org/cobit.htm) have focused on general IT management , without taking IT security spe-cifics into account. 2 Notable exceptions are security standards and guidelines from organizations such as the International Standards Organization/Inter-national Electrotechnical Commission (ISO/IEC) 3 and CERT. 4 The CERT handbook for security incident response 4 presents several SMMs and lists factors that organizations should take into account when choosing one, including the organization's size, security services, available resources, and organizational unit in which IT security professionals are embedded.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Ethical Perspective: Five Unacceptable Trade-offs on the Path to Universal Health Coverage

This article discusses what ethicists have called “unacceptable trade-offs” in health policy choices related to universal health coverage (UHC). Since the fiscal space is constrained, trade-offs need to be made. But some trade-offs are unacceptable on the path to universal coverage. Unacceptable choices include, among other examples from low-income countries, to expand coverage for services wit...

متن کامل

Goal-Oriented Security Trade-Off Modeling and Analysis with Knowledge Support

In designing software systems, security is typically only one design objective among many, which may compete with other objectives such as privacy and usability. Too often, security mechanisms are adopted without explicit recognition of competing design objectives and their origins in stakeholder interests. Ultimately, security is about balancing the trade-offs among the competing goals of mult...

متن کامل

Structured Systems Economics for Security Management

We develop an ontological account of information security architectures that is inspired by economic models of trade-offs between confidentiality, integrity, and availability. Our approach clarifies the nature of the trade-offs by making a clear distinction between declarative and operational concepts in security. We integrate this approach with a semantically justified mathematical systems mod...

متن کامل

Universal Health Coverage – The Critical Importance of Global Solidarity and Good Governance; Comment on “Ethical Perspective: Five Unacceptable Trade-offs on the Path to Universal Health Coverage”

This article provides a commentary to Ole Norheim’ s editorial entitled “Ethical perspective: Five unacceptable trade-offs on the path to universal health coverage.” It reinforces its message that an inclusive, participatory process is essential for ethical decision-making and underlines the crucial importance of good governance in setting fair priorities in healthcare. Solidarity on both natio...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2008