Balanced Design in Information Systems Security Planning
Daniel A. Stern
Abstract
Daniel A. Stern
Abstract
Information security is traditionally understood to involve technical security measures, such as intrusion prevention systems, to establish a secure perimeter around an organization’s sensitive information. Threats, then, are any potential attack on that secure perimeter with the intent of either obtaining unauthorized access or damaging availability or information. With modern organizations using tools to allow every employee to access information, and even allowing employees to control access restrictions on sensitive information, information security managers must expand their information security program to educate personnel and establish a culture of security. The expanded information systems security program must address technical, policy, standards and norms, education and cultural initiatives.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Information security is traditionally understood to involve technical security measures, such as intrusion prevention systems, to establish a secure perimeter around an organization’s sensitive information. Threats, then, are any potential attack on that secure perimeter with the intent of either obtaining unauthorized access or damaging availability or information. With modern organizations using tools to allow every employee to access information, and even allowing employees to control access restrictions on sensitive information, information security managers must expand their information security program to educate personnel and establish a culture of security. The expanded information systems security program must address technical, policy, standards and norms, education and cultural initiatives.
Key concepts: Computer security, Information security, Information security management, Information security standards, Certified Information Security Manager, Security information and event management, Standard of Good Practice, Computer science