vix.ing · top · new · best · stats · spec

Information Security Policy: A Management Practice Perspective

2016/05/28 by Moneer Alshaikh, Alshaikh, Moneer, Sean B. Maynard +5
Business, Management and Accounting · Computer Science · #Computers and Society (cs.CY) #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Information Technology Governance and Strategy #Information and Cyber Security #Network Security and Intrusion Detection #cs.CR #cs.CY

paper · pdf · doi:10.48550/arxiv.1606.00890

ISBN# 978-0-646-95337-3 Presented at the Australasian Conference on Information Systems 2015 (arXiv:1605.01032)

arxiv created 2016/05/28 · openalex publication_date 2016/05/28 · arxiv updated 2016/06/06 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

Considerable research effort has been devoted to the study of Policy in the domain of Information Security Management (ISM). However, our review of ISM literature identified four key deficiencies that reduce the utility of the guidance to organisations implementing policy management practices. This paper provides a comprehensive overview of the management practices of information security policy and develops a practice-based model that addresses the four aforementioned deficiencies. The model provides comprehensive guidance to practitioners on the activities security managers must undertake for security policy development and allows practitioners to benchmark their current practice with the models suggested best practice. The model contributes to theory by mapping existing information security policy research in terms of the defined management practices.

Citations

Related