Information security policy -: what do international information security standards say?

被引:91
|
作者
Höne, K [1 ]
Eloff, JHP [1 ]
机构
[1] Rand Afrikaans Univ, Dept Comp Sci, Johannesburg, South Africa
关键词
information security policy; international standards; information security; elements; characteristics;
D O I
10.1016/S0167-4048(02)00504-7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
One of the most important information security controls, is the information security policy. This vital direction-giving document is, however, not always easy to develop and the authors thereof battle with questions such as what constitutes a policy. This results in the policy authors turning to existing sources for guidance. One of these sources is the various international information security standards. These standards are a good starting Point for determining what the information security policy should consist of, but should not be relied upon exclusively for guidance. Firstly, they are not comprehensive in their coverage and furthermore, tending to rather address the processes needed for successfully implementing the information security policy. It is far more important the information security policy must fit in with the organisation's culture and must therefore be developed with this in mind.
引用
收藏
页码:402 / 409
页数:8
相关论文
共 50 条
  • [31] Ukrainian policy in the field of information security
    Pidbereznykh, Inna
    Koval, Oleg
    Solomin, Yevhen
    Kryvoshein, Vitaliy
    Plazova, Tetyana
    AMAZONIA INVESTIGA, 2022, 11 (60): : 206 - 213
  • [32] Information security standards for E-businesses
    Satti, M
    Garner, BJ
    Nagrial, MH
    ICCS 2002: 8TH INTERNATIONAL CONFERENCE ON COMMUNICATIONS SYSTEMS, VOLS 1 AND 2, PROCEEDINGS, 2002, : 641 - 645
  • [33] Information security management standards: Problems and solutions
    Siponen, Mikko
    Willison, Robert
    INFORMATION & MANAGEMENT, 2009, 46 (05) : 267 - 270
  • [34] Information security policy's impact on reporting security incidents
    Wiant, TL
    COMPUTERS & SECURITY, 2005, 24 (06) : 448 - 459
  • [35] Information Systems Security Risk Assessment. Harmonization with International Accounting Standards
    Munteanu, Adrian
    Fotache, Doina
    Dospinescu, Octavian
    2008 INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE FOR MODELLING CONTROL & AUTOMATION, VOLS 1 AND 2, 2008, : 1111 - 1117
  • [36] New impulse for information security with the revision of standards
    Nuovo impulso per la sicurezza delle informazioni con la revisione delle norme
    1600, Associazione Italiana per l'Informatica e il Calcolo Automatico, Piazzale Rodolfo Morandi, 2, Milano, 20121, Italy (13):
  • [37] State of standards in the information systems security area
    Fernandez-Medina, Eduardo
    Yaguee, Mariemma I.
    COMPUTER STANDARDS & INTERFACES, 2008, 30 (06) : 339 - 340
  • [38] INFORMATION SECURITY REGULATION IN INTERNATIONAL CONTEXT
    Matwyshyn, A.
    EDULEARN10: INTERNATIONAL CONFERENCE ON EDUCATION AND NEW LEARNING TECHNOLOGIES, 2010,
  • [39] The information revolution and international security.
    Webster, S
    INTERNATIONAL AFFAIRS, 1999, 75 (02) : 411 - 412
  • [40] The information revolution and international security.
    Bierling, S
    INTERNATIONALE POLITIK, 1999, 54 (2-3): : 108 - 108