2003Unpublished venueOpen access

Information Security Management System: Processes and Products

Mariki M. Eloff, Jan H. P. Eloff

Open full text 4 citations

Abstract

The executive and operational management of organisations today realise that the successful protection of information assets depend on a holistic approach towards the implementation of safeguards. A holistic approach requires that the focus of management should rather be on minimising overall risk exposure as opposed to “tick-off” security safeguards on a checklist. The holistic management of information security requires a well-established Information Security Management System (ISMS). An ISMS addresses all aspects in an organisation that deals with creating and maintaining a secure information environment. Aspects such as policies, standards, guidelines, codes-ofpractice, technology, human, legal and ethics issues all from part of an ISMS. Organisations can opt for different approaches to establishing an ISMS. One way is to implement the controls as contained in a standard or code-of-practice, such as ISO17799. In this case information security is driven from a management process point of view and referred to as “process security”. Another approach that also complement or add to process security, is to use certified products in the IT infrastructure environment when possible. The approach here focuses on technical issues and is referred to as “product security”. The ‘process’ ISMS and the ‘product’ ISMS approaches are only two ways to address information security, each from a different perspective. The question that arises is whether the ‘process’ ISMS and the ‘product’ ISMS can be combined into a more holistic ISMS and what the impact of the one will be on the other. The aim of this paper is.to propose an ISMS that combines “process security” and “product security”.

Open-access reader

About this research paper

What this paper is about

The executive and operational management of organisations today realise that the successful protection of information assets depend on a holistic approach towards the implementation of safeguards. A holistic approach requires that the focus of management should rather be on minimising overall risk exposure as opposed to “tick-off” security safeguards on a checklist. The holistic management of information security requires a well-established Information Security Management System (ISMS). An ISMS addresses all aspects in an organisation that deals with creating and maintaining a secure information environment. Aspects such as policies, standards, guidelines, codes-ofpractice, technology, human, legal and ethics issues all from part of an ISMS. Organisations can opt for different approaches to establishing an ISMS. One way is to implement the controls as contained in a standard or code-of-practice, such as ISO17799. In this case information security is driven from a management process point of view and referred to as “process security”. Another approach that also complement or add to process security, is to use certified products in the IT infrastructure environment when possible. The approach here focuses on technical issues and is referred to as “product security”. The ‘process’ ISMS and the ‘product’ ISMS approaches are only two ways to address information security, each from a different perspective. The question that arises is whether the ‘process’ ISMS and the ‘product’ ISMS can be combined into a more holistic ISMS and what the impact of the one will be on the other. The aim of this paper is.to propose an ISMS that combines “process security” and “product security”.

Why it matters

OpenAlex reports 4 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

The executive and operational management of organisations today realise that the successful protection of information assets depend on a holistic approach towards the implementation of safeguards. A holistic approach requires that the focus of management should rather be on minimising overall risk exposure as opposed to “tick-off” security safeguards on a checklist. The holistic management of information security requires a well-established Information Security Management System (ISMS). An ISMS addresses all aspects in an organisation that deals with creating and maintaining a secure information environment. Aspects such as policies, standards, guidelines, codes-ofpractice, technology, human, legal and ethics issues all from part of an ISMS. Organisations can opt for different approaches to establishing an ISMS. One way is to implement the controls as contained in a standard or code-of-practice, such as ISO17799. In this case information security is driven from a management process point of view and referred to as “process security”. Another approach that also complement or add to process security, is to use certified products in the IT infrastructure environment when possible. The approach here focuses on technical issues and is referred to as “product security”. The ‘process’ ISMS and the ‘product’ ISMS approaches are only two ways to address information security, each from a different perspective. The question that arises is whether the ‘process’ ISMS and the ‘product’ ISMS can be combined into a more holistic ISMS and what the impact of the one will be on the other. The aim of this paper is.to propose an ISMS that combines “process security” and “product security”.

Key concepts: Information security management system, Information security management, Information security, Standard of Good Practice, Information security standards, ITIL security management, Knowledge management, Process (computing)

Related papers

Back to paper searchBrowse research topicsOriginal source
Information Security Management System: Processes and Products — Research Paper | ScholarLens