Information Security Management has become a top management priority due to a highly increasing economical dependency on information
and its underlying information and communication technologies. While several efforts have been undertaken to set up physical,
technical and organizational concepts to secure the information infrastructure, economic aspects have been widely neglected
despite of an increasing management interest. This paper presents a layered model for managing information security with a
strong economic focus by introducing a comprehensive concept which specifically links business and information security goals.
Keywords information security management - information management - strategic management - business goals - business alignment - business IT alignment - financial management - return on security investment