An Integrative Alignment Approach for Information Security Policy in the Context of Strategic Planning
نویسنده
چکیده
The enterprise information security policy is derived from the strategic requirements for risk management and corporate governance. Consistent alignment between the security policy and the other corporate business policies and strategies has to be maintained if information security is to be implemented according to evolving business objectives. There are however limitations in current approaches for developing and managing the security policy to facilitate consistent strategic alignment within the business strategic planning cycle. The proposed full integrative planning approach for the enterprise information security policy conceptually demonstrates that the security policy can be presented as a business policy within the strategic management cycle. As such, this paper argues that the security policy can take on integrated strategic planning activities alongside other strategic business policies. The recommended future research includes the adoption of the proposed security policy framework to establish applicability and the development of an assessment model for both the framework and the security policy. This is to validate the framework propositions and identify elements of value as well as areas for improvement.
منابع مشابه
Critical Success Factors in implementing information security governance (Case study: Iranian Central Oil Fields Company)
The oil industry, as one of the main industries of the country, has always faced cyber attacks and security threats. Therefore, the integration of information security in corporate governance is essential and a governance challenge. The integration of information security and corporate governance is called information security governance. In this research, we identified "critical success factor...
متن کاملOptimal Strategies of Increasing Business Alignment, in Social Security Organization, with Quality Function Deployment (QFD) Approach
Considering the importance of the concept of strategic alignment of information technology (IT) in today economic organizations, this study attempted to extract the organization's IT strategies in order to increase the degree of strategic alignment and consequently the optimal strategies in the field of marketing and service delivery for social security organization. Using QFD technique and hie...
متن کاملA Model of International Marketing Strategic Implementation in the Downstream Sector of Iran’s Petroleum Industry
Abstract Purpose and Necessity of Research: Given that at the strategic level a model for implementing international marketing strategies was not observed, it is necessary to classify the issues raised in international marketing in order to provide a reference model to define the position in the area of strategic and operational issues of this function based on it, to create alignm...
متن کاملOrganizational Information Architecture Meta-Method for Organizational Website, Case study: Central Insurance of the Islamic Republic of Iran
Background and Aim: Information Architecture is an organizational meta-method that adopts a strategic approach to the specialized information of the organization using an integrated framework and enables the management of organizational resources by acquiring and upgrading new information technologies. Therefore, it is essential to be part of the current processes of the organization and the in...
متن کاملIdentifying and Ranking Technology-Telecommunications Context of Information Security anagement System in E-Government Using Fuzzy AHP Approach
In recent years, many security threats have entered into the organizations’ information and changed the organizational performance resulting in their exorbitant costs. This question is of particular importanceabout government agencies that use information and Internet systems. This issue enabled the top managers of organizations to implement a security system and minimize these costs. Using In...
متن کامل