Lecture Notes in Computer Science, 2007, Volume 4680/2007, 224-237, DOI: 10.1007/978-3-540-75101-4_21

Learning from Your Elders: A Shortcut to Information Security Management Success

Finn Olav Sveen, Jose Manuel Torres and Jose Maria Sarriegi

View Related Documents

Abstract

Knowledge Management (KM), Quality Management (QM) and Safety Management (SM) are mature fields that have evolved and improved over time. Information security management (ISM) has aspects of these fields. E.g. tougher customer demands require continuous quality improvement, while new threats create a need for constantly improved security. Information technology brings new opportunities, but also challenges for KM, as it does for security. Organizations must comply with increasingly stricter safety laws, analogous to ISM requirements given by e.g. the Sarbanes-Oxley act. Research and practical experiences in KM, QM and SM have generated valuable insights that the younger, immature field of ISM can learn from. We present ten lessons and apply them to ISM. Key insights include the emphasis of good implementation over selection of model, the necessity of multi disciplinary teams, long term thinking, measurement, visualizing security costs, benchmarking, continuous improvement, collaboration, going beyond compliance and security as a competitive advantage.

Keywords  Information Security Management - Knowledge Management - Quality Improvement - Safety Management

Fulltext Preview

Image of the first page of the fulltext document