Achieving Business Value in Information Security
- Art: Diplomarbeit
- Autor: Torsten Kriedt
- Abgabedatum: Dezember 2001
- Umfang: 99 Seiten
- Dateigröße: 873,4 KB
- Note: 1,3
- Institution / Hochschule: Fachhochschule Regensburg Deutschland
- ISBN (eBook): 978-3-8324-6009-9
-
ISBN (Paperback) :
978-3-8324-6009-9 P - ISBN (CD) :978-3-8324-6009-9 CD
- Sprache: Englisch
- Prämierung:
- Arbeit zitieren: Kriedt, Torsten Dezember 2001: Achieving Business Value in Information Security, Hamburg: Diplomica Verlag
- Schlagworte: Maturity Model, Balanced Scorecard, Change Management, Knowledge Management, Enterprise Model
In den Warenkorb
58,00 €
Diplomarbeit von Torsten Kriedt
Abstract:
The beginning of the 21st century with the fear of the "Year 2000"-threat (Y2K) became a milestone for the "Information Age", a term coined for the post-industrial stage of leading countries „[…] when information and information technologies become the main strategic national resource which results in an avalanche growth of information dependence in all spheres of society and state activities.”. In organisations the awareness of the dependence on information has led to corporate initiatives to treat information as an asset, which includes various efforts for its protection. Management trends such as "knowledge management" have identified "knowledge sharing" as a new means for achieving competitive advantage, thus promoting information to be disseminated. Due to an ever closer relationship with customers, suppliers and even competitors, organisations have expanded their "information network" outside of the original boundaries.
The dualism of protection of information assets on the one hand and a free flow of information has been identified to become a challenge for organisations, described as „[…] how to satisfy this need to share information without exposing the organization to undue risk.”. With the information society implying radical changes, the need to act has been accelerated by a new mindset reacting to the advent of "e-business".
Information Security (InfoSec) is often mistaken to be a purely technical issue, handled by information system (IS) departments and used as a synonym for firewall, access controls, and encryption of e-mails. However, because of the risks involved for an organisation - including legal liabilities, loss of trust and severe financial damage - InfoSec needs to be a top management issue. Then again, although paying lip-service to treating information as an asset, top-management usually does not act upon it: the average InfoSec spending in the U.S. today is only 0.4 percent of an organisation’s revenue.
In the following work it will be shown that a new approach to and a new understanding of InfoSec is vital for organisations to excel in the challenges faced by the information environment of the 21st century. The key focus of this study is to link existing InfoSec approaches to the concept of business value by ensuring their strategic fit with the corporate objectives. The first part will provide a common foundation with an evaluation of the role of information for organisations, relevant trends in the corporate environment, their impact on InfoSec, and its resulting working hypothesis. This understanding will then be used to evaluate the components of an InfoSec framework and current approaches to InfoSec. Building on the key aspects of InfoSec pointed out in the first part, the second part introduces a model based on business value as a means to enable an organisation’s co-ordinated transformation towards integrated InfoSec management.
Table of Contents:
| List of Acronyms | IV | |
| I. | Introduction | 1 |
| 1. | The Information Flow Dualism | 1 |
| 2. | Information Security: An Executive Issue | 1 |
| 3. | Outline & Objective of This Work | 2 |
| Part I: Re-defining Information Security | 3 | |
| II. | Scanning the Information Environment | 4 |
| A. | Information as an Asset | 4 |
| 1. | A Primer on Information | 4 |
| 2. | Intellectual Capital Management | 6 |
| 3. | The Value of Information – a Pragmatic View | 9 |
| B. | Environmental Analysis | 11 |
| 1. | Organisational Trends | 11 |
| 2. | The Changing Role of Information Technology | 15 |
| 3. | Legal Requirements | 16 |
| C. | Impact on Information Security | 17 |
| 1. | Information Security Working Hypothesis | 17 |
| III. | Key Aspects of Information Security | 20 |
| A. | The Framework | 20 |
| 1. | Linking Information Security to Risk Management | 20 |
| B. | Components of Information Security | 22 |
| 1. | People & Organisation | 22 |
| 2. | Processes | 27 |
| 3. | Security Architecture | 33 |
| C. | Current Information Security Approaches | 34 |
| 1. | Overview | 34 |
| 2. | The Need for an Integrated Approach | 38 |
| Part II: Value-Based Transformation Towards Integrated Information Security | 40 | |
| IV. | Achieving Integrated Information Security | 41 |
| A. | Knowing the Destination | 41 |
| 1. | Integrated Information Security | 41 |
| 2. | The Business Value of Information Security | 43 |
| B. | Co-ordinated Transformation | 47 |
| 1. | The Need for a Roadmap | 47 |
| 2. | The Information Security Maturity Model | 49 |
| 3. | The Measurement Architecture | 52 |
| 4. | The Maturity Levels Characterised | 61 |
| 5. | Avoiding Pitfalls in the Implementation Process | 67 |
| 6. | Evaluation | 69 |
| V. | Conclusion | 71 |
| VI. | List of Figures | 74 |
| VII. | Bibliography | 75 |
| 1. | Used for Citation | 75 |
| 2. | Used for Context Research | 83 |
| VIII. | Appendix | 87 |
| 1. | Information Security Cause-and-Effect Diagram | 88 |
| 2. | Change Options Matrix | 89 |
| 3. | Information Security Capability Matrix | 90 |
In den Warenkorb
58,00 €
Link zur Arbeit:
http://www.diplom.de/ean/9783832460099
Arbeit zitieren:
Kriedt, Torsten Dezember 2001: Achieving Business Value in Information Security, Hamburg: Diplomica Verlag
Schlagworte:
Maturity Model, Balanced Scorecard, Change Management, Knowledge Management, Enterprise Model



