• DocumentCode
    1958518
  • Title

    A Multi-stage Methodology for Ensuring Appropriate Security Culture and Governance

  • Author

    Ghernouti-Helie, S. ; Tashi, Igli ; Simms, David

  • Author_Institution
    Fac. of Bus. & Econ., Univ. of Lausanne, Lausanne, Switzerland
  • fYear
    2010
  • fDate
    15-18 Feb. 2010
  • Firstpage
    353
  • Lastpage
    360
  • Abstract
    The assessment of the adequacy and appropriateness of the security infrastructure in place within an organization poses a significant challenge to those responsible for security management, those responsible for corporate compliance, and senior management who seek a reasonable balance between robust security and ease of use for legitimate users. The process of assessment, validation and improvement is continuous and follows a number of clearly defined steps, each of which builds on the comfort obtained from the previous one and which confirms the consistency of the measures in place with the overall strategy and policies, all the while referring to the specific context and requirements of the organization. This paper describes a framework for the assessment of security governance that can be applied to organizations in the public and private sectors with differing security cultures, discusses the methods of implementing, tailoring the methodology and evaluating the results of the analysis, details a number of critical success factors, and concludes with a case study from the manufacturing sector.
  • Keywords
    organisational aspects; security of data; assessment process; critical success factors; improvement process; manufacturing sector; security culture; security governance; security infrastructure; security management; senior management; validation process; Availability; Business; Computer security; Conference management; Information security; Law; Protection; Pulp manufacturing; Risk management; Robustness; assessment methodology; governance criteria; information security governance; legal conformity; organizational culture; risk management; security awareness; user compliance;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability, and Security, 2010. ARES '10 International Conference on
  • Conference_Location
    Krakow
  • Print_ISBN
    978-1-4244-5879-0
  • Type

    conf

  • DOI
    10.1109/ARES.2010.118
  • Filename
    5438069