Bachelor + Master Publishing
810 Bachelorarbeiten, 531 Masterarbeiten, 10.101 Diplomarbeiten

Achieving Business Value in Information Security

Achieving Business Value in Information Security
Über dieses Buch
  • Art: Diplomarbeit
  • Autor: Torsten Kriedt
  • Abgabedatum: Dezember 2001
  • Umfang: 99 Seiten
  • Dateigröße: 873,4 KB
  • Note: 1,3
  • Institution / Hochschule: Fachhochschule Regensburg Deutschland
  • ISBN (eBook): 978-3-8324-6009-9
  • ISBN (Paperback) :
    978-3-8324-6009-9 P
  • ISBN (CD) :978-3-8324-6009-9 CD
  • Sprache: Englisch
  • Prämierung:
  • Arbeit zitieren: Kriedt, Torsten Dezember 2001: Achieving Business Value in Information Security, Hamburg: Diplomica Verlag
  • Schlagworte: Maturity Model, Balanced Scorecard, Change Management, Knowledge Management, Enterprise Model

Diplomarbeit von Torsten Kriedt

Abstract:

The beginning of the 21st century with the fear of the "Year 2000"-threat (Y2K) became a milestone for the "Information Age", a term coined for the post-industrial stage of leading countries „[…] when information and information technologies become the main strategic national resource which results in an avalanche growth of information dependence in all spheres of society and state activities.”. In organisations the awareness of the dependence on information has led to corporate initiatives to treat information as an asset, which includes various efforts for its protection. Management trends such as "knowledge management" have identified "knowledge sharing" as a new means for achieving competitive advantage, thus promoting information to be disseminated. Due to an ever closer relationship with customers, suppliers and even competitors, organisations have expanded their "information network" outside of the original boundaries.

The dualism of protection of information assets on the one hand and a free flow of information has been identified to become a challenge for organisations, described as „[…] how to satisfy this need to share information without exposing the organization to undue risk.”. With the information society implying radical changes, the need to act has been accelerated by a new mindset reacting to the advent of "e-business".

Information Security (InfoSec) is often mistaken to be a purely technical issue, handled by information system (IS) departments and used as a synonym for firewall, access controls, and encryption of e-mails. However, because of the risks involved for an organisation - including legal liabilities, loss of trust and severe financial damage - InfoSec needs to be a top management issue. Then again, although paying lip-service to treating information as an asset, top-management usually does not act upon it: the average InfoSec spending in the U.S. today is only 0.4 percent of an organisation’s revenue.

In the following work it will be shown that a new approach to and a new understanding of InfoSec is vital for organisations to excel in the challenges faced by the information environment of the 21st century. The key focus of this study is to link existing InfoSec approaches to the concept of business value by ensuring their strategic fit with the corporate objectives. The first part will provide a common foundation with an evaluation of the role of information for organisations, relevant trends in the corporate environment, their impact on InfoSec, and its resulting working hypothesis. This understanding will then be used to evaluate the components of an InfoSec framework and current approaches to InfoSec. Building on the key aspects of InfoSec pointed out in the first part, the second part introduces a model based on business value as a means to enable an organisation’s co-ordinated transformation towards integrated InfoSec management.

Table of Contents:

List of Acronyms IV
I. Introduction 1
1. The Information Flow Dualism 1
2. Information Security: An Executive Issue 1
3. Outline & Objective of This Work 2
Part I: Re-defining Information Security 3
II. Scanning the Information Environment 4
A. Information as an Asset 4
1. A Primer on Information 4
2. Intellectual Capital Management 6
3. The Value of Information – a Pragmatic View 9
B. Environmental Analysis 11
1. Organisational Trends 11
2. The Changing Role of Information Technology 15
3. Legal Requirements 16
C. Impact on Information Security 17
1. Information Security Working Hypothesis 17
III. Key Aspects of Information Security 20
A. The Framework 20
1. Linking Information Security to Risk Management 20
B. Components of Information Security 22
1. People & Organisation 22
2. Processes 27
3. Security Architecture 33
C. Current Information Security Approaches 34
1. Overview 34
2. The Need for an Integrated Approach 38
Part II: Value-Based Transformation Towards Integrated Information Security 40
IV. Achieving Integrated Information Security 41
A. Knowing the Destination 41
1. Integrated Information Security 41
2. The Business Value of Information Security 43
B. Co-ordinated Transformation 47
1. The Need for a Roadmap 47
2. The Information Security Maturity Model 49
3. The Measurement Architecture 52
4. The Maturity Levels Characterised 61
5. Avoiding Pitfalls in the Implementation Process 67
6. Evaluation 69
V. Conclusion 71
VI. List of Figures 74
VII. Bibliography 75
1. Used for Citation 75
2. Used for Context Research 83
VIII. Appendix 87
1. Information Security Cause-and-Effect Diagram 88
2. Change Options Matrix 89
3. Information Security Capability Matrix 90

Arbeit zitieren:
Kriedt, Torsten Dezember 2001: Achieving Business Value in Information Security, Hamburg: Diplomica Verlag

Schlagworte:
Maturity Model, Balanced Scorecard, Change Management, Knowledge Management, Enterprise Model

diplom.de
Bachelor + Master Publishing

Hermannstal 119 k
22119 Hamburg

Fon: +49 (0) 40 655992-0
Fax: +49 (0) 40 655992-22

Service-Telefon

Rufen Sie uns an:
+49 (0) 40 655992-0

Mo-Fr
09.00-16.00 Uhr

diplom.de in den Medien

Folgen Sie uns bei Twitter & werden Sie diplom.de-Fan bei Facebook!
Schreibtipps unserer Lektoren, Neuigkeiten aus dem Verlagsalltag und das Expertenwissen unserer Autoren als Tweet & Post!
Wir freuen uns auf Sie!

diplom.de BACHELOR + MASTER PUBLISHING

Bachelorarbeiten, Masterarbeiten, Diplomarbeiten, Magisterarbeiten, Dissertationen und andere Abschlussarbeiten aus allen Fachbereichen und Hochschulen können Sie bei uns als eBook sofort per Download beziehen oder sich auf CD oder als Buch zusenden lassen. Seit mehr als 15 Jahren ist diplom.de der seriöse, professionelle und erfolgreiche Partner für die Veröffentlichung wissenschaftlicher Abschlussarbeiten.

© Diplomica Verlag GmbH 1996-2011, AG Hamburg HRB 80293 - GF Björn Bedey, USt-IdNr.: DE214910002 - Verkehrsnummer: 12285 - Impressum
Index der Arbeiten - Index der Autoren