Information Systems Security Strategy: A Process View
dc.contributor.author | Baskerville, Richard | |
dc.contributor.author | Dhillon, G. | |
dc.contributor.editor | D W Straub | |
dc.contributor.editor | S Goodman | |
dc.contributor.editor | R Baskerville | |
dc.date.accessioned | 2017-01-30T13:10:19Z | |
dc.date.available | 2017-01-30T13:10:19Z | |
dc.date.created | 2015-07-16T07:04:23Z | |
dc.date.issued | 2008 | |
dc.identifier.citation | Baskerville, R. and Dhillon, G. 2008. Information Systems Security Strategy: A Process View, in Straub, D. and Goodman, S. and Baskerville, R. (ed), Information Security: Policy, Processes, and Practices, pp. 15-45. Armonk: M E Sharpe. | |
dc.identifier.uri | http://hdl.handle.net/20.500.11937/29094 | |
dc.description.abstract |
This chapter adopts a process view of information security strategy. That is, it is centrally concerned with how to "make" strategy; this extends the concern about what strategy "is." From a process viewpoint, information security strategy involves one or more strategy-setting processes. Such processes require an assessment of the goals for organizational information security. Examples include compliance with regulatory requirements, national and international standards, and professional practices. The strategy-setting process may be organized using a product criterion or a process criterion. A product criterion would organize the strategy-setting process by grouping activities according to the end products of the process. The products of strategy setting include statements of vision, core values, rationale, and strategic plans such as the security organization structure, security operations, and security budgeting strategy. A process criterion would organize the strategy-setting process by grouping activities according to major components, such as the alignment of security with organizational strategy, the planning of operational strategies, and the planning of security organizations. This chapter elaborates not just security goals, but the goal assessment process; not just the security criteria, but the criterion organizing processes; and not just the products of the strategic processes, but the strategy-setting processes themselves. | |
dc.publisher | M E Sharpe Inc | |
dc.title | Information Systems Security Strategy: A Process View | |
dc.type | Book Chapter | |
dcterms.source.title | Information Security: Policy, Processes, and Practices | |
dcterms.source.isbn | 9780765617187 | |
dcterms.source.place | NA | |
dcterms.source.chapter | 11 | |
curtin.department | School of Information Systems | |
curtin.accessStatus | Fulltext not available |