Assessment of Enterprise Information Security - The Importance of Prioritization

  • Authors:
  • Erik Johansson;Pontus Johnson

  • Affiliations:
  • Royal Institute of Technology (KTH);Royal Institute of Technology (KTH)

  • Venue:
  • EDOC '05 Proceedings of the Ninth IEEE International EDOC Enterprise Computing Conference
  • Year:
  • 2005

Quantified Score

Hi-index 0.01

Visualization

Abstract

Assessing the level of information security in an enterprise is a serious challenge for many organizations. This paper considers the prioritization of the field of enterprise information security. The paper thus considers how we may know what parts of information security are important for a company to address and what parts are not. Two methods for prioritization are used. The results demonstrate to what extent different standards committees, guideline authors and expert groups differ in their opinions on what the important issues are in enterprise information security. The ISO/IEC 17799, the NIST SP 800-26, the ISF standards committees, the CMU/SEI OCTAVE framework authors and an expert panel at the Swedish Information Processing Society (DFS) are considered. The differences in prioritization have important consequences on enterprise information security assessments. The effects on the information security assessment results in a European energy company are presented in the paper.