2005Unpublished venueRequires access

A Framework for Information Security Risk Management Communication.

Werner Bornman, Les Labuschagne

Open publisher page 6 citations

Abstract

Organisations have over the last couple of years become more aware of the importance of information security risk management and its corresponding due diligence requirements. A cornucopia of information security risk management approaches exist that can assist organisations in determining and controlling risks. However, with these choices organisations are finding it increasingly difficult to communicate the information security risks to the strategic level or for strategic management to communicate information security goals to the organisation. An approach is necessary that will enable organisations to communicate information security risk information to strategic level management quickly and unambiguously. This approach will have to provide information in accordance with corporate governance requirements and be based on best practice. This article suggests a framework that was developed from best practice and industry standards, and takes into consideration various information security risk management approaches.

About this research paper

What this paper is about

Organisations have over the last couple of years become more aware of the importance of information security risk management and its corresponding due diligence requirements. A cornucopia of information security risk management approaches exist that can assist organisations in determining and controlling risks. However, with these choices organisations are finding it increasingly difficult to communicate the information security risks to the strategic level or for strategic management to communicate information security goals to the organisation. An approach is necessary that will enable organisations to communicate information security risk information to strategic level management quickly and unambiguously. This approach will have to provide information in accordance with corporate governance requirements and be based on best practice. This article suggests a framework that was developed from best practice and industry standards, and takes into consideration various information security risk management approaches.

Why it matters

OpenAlex reports 6 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Organisations have over the last couple of years become more aware of the importance of information security risk management and its corresponding due diligence requirements. A cornucopia of information security risk management approaches exist that can assist organisations in determining and controlling risks. However, with these choices organisations are finding it increasingly difficult to communicate the information security risks to the strategic level or for strategic management to communicate information security goals to the organisation. An approach is necessary that will enable organisations to communicate information security risk information to strategic level management quickly and unambiguously. This approach will have to provide information in accordance with corporate governance requirements and be based on best practice. This article suggests a framework that was developed from best practice and industry standards, and takes into consideration various information security risk management approaches.

Key concepts: Information security management, Information security, Risk management, Information governance, Security management, Certified Information Security Manager, Security information and event management, Risk management information systems

Related papers

Back to paper searchBrowse research topicsOriginal source
A Framework for Information Security Risk Management Communication. — Research Paper | ScholarLens