An Information Security Governance Framework

  • Authors:
  • A. Da Veiga;J. H. P. Eloff

  • Affiliations:
  • University of Pretoria, South Africa;Department of Computer Science, University of Pretoria, South Africa

  • Venue:
  • Information Systems Management
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Information security culture develops in an organization due to certain actions taken by the organization. Management implements information security components, such as policies and technical security measures with which employees interact and that they include in their working procedures. Employees develop certain perceptions and exhibit behavior, such as the reporting of security incidents or sharing of passwords, which could either contribute or be a threat to the securing of information assets. To inculcate an acceptable level of information security culture, the organization must govern information security effectively by implementing all the required information security components. This article evaluates four approaches towards information security governance frameworks in order to arrive at a complete list of information security components. The information security components are used to compile a new comprehensive Information Security Governance framework. The proposed governance framework can be used by organizations to ensure they are governing information security from a holistic perspective, thereby minimising risk and cultivating an acceptable level of information security culture.