Information security policy -: what do international information security standards say?

被引:91
|
作者
Höne, K [1 ]
Eloff, JHP [1 ]
机构
[1] Rand Afrikaans Univ, Dept Comp Sci, Johannesburg, South Africa
关键词
information security policy; international standards; information security; elements; characteristics;
D O I
10.1016/S0167-4048(02)00504-7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
One of the most important information security controls, is the information security policy. This vital direction-giving document is, however, not always easy to develop and the authors thereof battle with questions such as what constitutes a policy. This results in the policy authors turning to existing sources for guidance. One of these sources is the various international information security standards. These standards are a good starting Point for determining what the information security policy should consist of, but should not be relied upon exclusively for guidance. Firstly, they are not comprehensive in their coverage and furthermore, tending to rather address the processes needed for successfully implementing the information security policy. It is far more important the information security policy must fit in with the organisation's culture and must therefore be developed with this in mind.
引用
收藏
页码:402 / 409
页数:8
相关论文
共 50 条
  • [1] Trends of international standards for information security technology
    Moriai, S
    Fujioka, A
    NTT REVIEW, 2003, 15 (02): : 47 - 52
  • [2] International and national standards on societal information security
    Lykhova, Sofiia
    Sysoieva, Viktoriia
    Servatiuk, Liudmyla
    Shamsutdinov, Oleksandr
    Hurina, Dariia
    REVISTA CIENTIFICA GENERAL JOSE MARIA CORDOVA, 2024, 20 (38):
  • [3] Information security matters: What is information security worth?
    Ross, Steven J.
    ISACA Journal, 2019, 2 : 4 - 6
  • [4] Information security policy
    Mead, N
    Anderson, R
    McGraw, G
    Machanick, P
    Bollinger, T
    Shimeall, T
    Pyster, A
    Brown, D
    Draier, E
    Schmidt, H
    IEEE SOFTWARE, 2000, 17 (05) : 26 - 32
  • [5] INTERNATIONAL INFORMATION SECURITY
    Voznyuk, Yevhenija
    Kunytskyy, Mykhaylo
    Mykhaliuk, Nazar
    Novak, Oleksandr
    AD ALTA-JOURNAL OF INTERDISCIPLINARY RESEARCH, 2021, 11 (01): : 381 - 385
  • [6] Nurse Information Security Policy Compliance, Information Competence, and Information Security Attitudes Predict Information Security Behavior
    Kang, Purum
    Kang, Jiwon
    Monsen, Karen A.
    CIN-COMPUTERS INFORMATICS NURSING, 2023, 41 (08) : 595 - 602
  • [7] Information Security Policy Compliance: The Role of Information Security Awareness
    AL-Omari, Ahmad
    El-Gayar, Omar
    Deokar, Amit
    AMCIS 2012 PROCEEDINGS, 2012,
  • [8] Information Policy: Does Information Policy lead to Information Security?
    Alhussain, Abdullah
    EDUCATION EXCELLENCE AND INNOVATION MANAGEMENT THROUGH VISION 2020, 2019, : 6520 - 6523
  • [9] Internalization of Information Security Policy and Information Security Practice: A Comparison with Compliance
    Park, Minjung
    Chai, Sangmi
    PROCEEDINGS OF THE 51ST ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES (HICSS), 2018, : 4723 - 4731
  • [10] Information Security Culture or Information Safety Culture What do Words Convey?
    Ilvonen, Ilona
    PROCEEDINGS OF THE 10TH EUROPEAN CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2011, : 148 - 154