DocumentCode :
1803824
Title :
A software gateway to affordable and effective Information Security Governance in SMMEs
Author :
Coertze, Jacques ; Von Solms, Rossouw
Author_Institution :
Inst. for ICT Advancement, Nelson Mandela Metropolitan Univ., Port Elizabeth, South Africa
fYear :
2013
fDate :
14-16 Aug. 2013
Firstpage :
1
Lastpage :
8
Abstract :
It has been found that many small, medium and micro enterprises (SMMEs) do not comply with sound information security governance principles, specifically those principles involved in drafting information security policies and monitoring compliance, mainly as a result of restricted resources and expertise. Research suggests that this problem occurs worldwide and that the impact it has on SMMEs is great. In previous research an information security governance model was established to assist SMMEs in addressing information security governance issues and concerns. In order to provide SMMEs with a practical approach for applying this model, further research was conducted to establish a software program that demonstrates the model´s practical feasibility. The aim of this paper is to introduce this software program, called The Information Security Governance Toolbox (ISGT), by means of its various components, workings and benefits. Furthermore, a focus-group study´s evaluation results are offered that suggest that the program is useful to SMMEs in addressing their information security governance implementation challenges and offer value for industry.
Keywords :
security of data; small-to-medium enterprises; ISGT; SMME; The Information Security Governance Toolbox; information security governance principles; information security policies; monitoring compliance; small-medium-microenterprises; software gateway; software program; Companies; Documentation; Information security; Software; Standards; IT governance; automation; corporate governance; enterprise security; information security; information security governance; managing information security; methodologies for securing small/medium size enterprises; security policy and procedures;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Security for South Africa, 2013
Conference_Location :
Johannesburg
Type :
conf
DOI :
10.1109/ISSA.2013.6641035
Filename :
6641035
Link To Document :
بازگشت