2006
DOI: 10.1016/j.cose.2006.07.005
|View full text |Cite
|
Sign up to set email alerts
|

Information Security Governance: A model based on the Direct–Control Cycle

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
50
0

Year Published

2008
2008
2021
2021

Publication Types

Select...
6

Relationship

1
5

Authors

Journals

citations
Cited by 81 publications
(50 citation statements)
references
References 0 publications
0
50
0
Order By: Relevance
“…While information security governance research fail to offers detailed guidance on how to develop information security policies [e.g. 13], there exists practitioner-oriented literature that do [14,15]. However, this literature focuses on design guidelines without reflecting on the end products' usefulness from an employee perspective.…”
Section: Information Security Policy Theoriesmentioning
confidence: 99%
“…While information security governance research fail to offers detailed guidance on how to develop information security policies [e.g. 13], there exists practitioner-oriented literature that do [14,15]. However, this literature focuses on design guidelines without reflecting on the end products' usefulness from an employee perspective.…”
Section: Information Security Policy Theoriesmentioning
confidence: 99%
“…In order to measure, there exists a need to identify and collect the correct information to measure against [7]. Any directive issued by the board which cannot be measured in some particular way is of little value because compliance and adequate control cannot be achieved [7]. The board should extend this strategic directing and controlling responsibility into IT to ensure that it supports the corporate vision and mission.…”
Section: Directing and Controllingmentioning
confidence: 99%
“…These directives need to be translated into organizational policies, standards and procedures, which will enable strategic, tactical and operational alignment with the company's corporate vision and mission. The board also needs to control an organization by ensuring that there is compliance with all directives, policies, standards, procedures and any relevant laws and regulations [7]. Therefore, to properly control (i.e., manage), thus ensuring compliance with directives and policies, there exists a need to measure.…”
Section: Directing and Controllingmentioning
confidence: 99%
See 2 more Smart Citations