IT Security Governance: A Framework based on ISO 38500

نویسندگان

  • Suchit Ahuja
  • Yolande E. Chan
چکیده

ISO 38500 is an international standard for IT governance. The guidelines of ISO 38500 can also be applied at the IT security functional level in order to guide the governance of IT security. This paper proposes the use of a strategic information security management (ISM) framework to implement guidelines of ISO 38500. This approach provides several strategic advantages to the organization by 1) aligning IT security initiatives to business strategy; 2) providing a mechanism for establishing and tracking security metrics; and 3) enhancing the overall maturity of business, IT and IT security processes. The framework also leverages tools such as COBIT, the Balanced Scorecard and SSE-CMM in order to implement IT security governance and continuous improvement practices. Using extant literature, this paper identifies certain challenges and solutions with respect to the governance of IT security. For practitioners, it highlights relevant links between principles of ISO 38500 and IT governance, provides an over-arching contextual framework to drive IT security governance, and demonstrates mitigation solutions for IT security governance challenges. For academics, the paper makes theoretical contributions, by relating IT security governance to business strategy and proposing that firms develop dynamic governance capabilities (Pavlou and El Sawy, 2010) or organizational learning ladders (Ciborra and Andreu, 2010).

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Investigation of the Comprehensiveness of the ISO/IEC 38500:2008 Standard in an Inter-organisational Public/Private-sector Context

In this study we evaluate ISO/IEC 38500:2008, the Corporate Governance of Information Technology standard, as a design artefact in the context of development and deployment of a large IT system in a public/private-sector context. The findings show that ISO/IEC 38500:2008 has merit as an analytical framework, providing a good basis upon which to objectively evaluate the corporate governance of I...

متن کامل

Corporate Governance of IT: A Case Study in An Australian Government Department

Harnessing the power from Information Technology (IT) has been a focus of research and practice for many decades, yet statistics show that many organizations are yet to fully realize the value from investment in IT. Whilst numerous frameworks and standards have been published to help organizations achieve value from IT investment, research demonstrating whether newer standards have manifested s...

متن کامل

An Integrated Security Governance Framework for Effective PCI DSS Implementation

This paper analyses relevant IT governance and security frameworks/standards used in IT assurance and security to propose an integrated framework for ensuring effective PCI DSS implementation. Merchants dealing with credit cards have to comply with the Payment Card Industry Data Security Standards (PCI DSS) or face penalties for non-compliance. With more transactions based on credit cards, merc...

متن کامل

A theoretical model for the corporate governance of It

Empirical studies into the governance of Information Technology (IT) have advanced our understanding of the mechanisms used to control the management of IT. However, there has been relatively little research into the formulation of a theoretical model of IT governance that explains and organises the growing collection of mechanisms into a coherent whole. To further advance the concept of the co...

متن کامل

Maturity Model for IT Service Outsourcing in Higher Education Institutions

The current success of organizations depends on the successful implementation of Information and Comunication Technologies (ICTs). Good governance and ICT management are essential for delivering value, managing technological risks, managing resources and performance measurement. In addition, outsourcing is a strategic option which complements IT services provided internally in organizations. Th...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2015