2005
DOI: 10.1016/j.cose.2005.07.003
|View full text |Cite
|
Sign up to set email alerts
|

Information Security Governance – Compliance management vs operational management

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
34
0
1

Year Published

2007
2007
2022
2022

Publication Types

Select...
5
3
1

Relationship

0
9

Authors

Journals

citations
Cited by 89 publications
(35 citation statements)
references
References 1 publication
0
34
0
1
Order By: Relevance
“…Most comprise of auditing, risk management and information security management (von Solms, 2005). Other models view security governance as independent layers within an organisational structure from operational and human resourced based through tactical security controls and risk management to strategic business strategy direction (Business Software Alliance, 2003;Harris, 2006b;Nixu, 2008).…”
Section: A Governance Approachmentioning
confidence: 98%
“…Most comprise of auditing, risk management and information security management (von Solms, 2005). Other models view security governance as independent layers within an organisational structure from operational and human resourced based through tactical security controls and risk management to strategic business strategy direction (Business Software Alliance, 2003;Harris, 2006b;Nixu, 2008).…”
Section: A Governance Approachmentioning
confidence: 98%
“…The first constructor was a review of the literature on current information governance thinking, where it was noted that there exists a discrepancy between the compliance to information governance objectives and the operational management tasks to meet these objectives (von Solms, 2005). This is further confirmed by the interview data concerning the responsibilities and legal requirements of information security.…”
Section: Model Constructionmentioning
confidence: 77%
“…This is due to the fact that information security governance is accepted as an integral part of Corporate Governance (Von Solms, 2005). Corporate governance relates to the responsibility of the board to effectively direct and control an organization through sound leadership efforts (Donaldson, 2005).…”
Section: Strategic Levelmentioning
confidence: 99%
“…It is essential to measure and enforce compliance (Von Solms, 2005), and both technology and employee behavior should be monitored to ensure compliance with information security policies and to respond effectively and timely to incidents detected (Vroom and Von Solms, 2004). Monitoring of employee behavior could include monitoring the installation of unauthorized software, the use of strong passwords or Internet sites visited.…”
Section: Tactical and Operational Levelmentioning
confidence: 99%