2005Journal of the Association for Information SystemsRequires access

The Interrelationship Between Objectives and Practices in Information Security Management.

Qingxiong Ma, John Pearson

Open publisher page 0 citations

Abstract

To help practitioners effectively implement security programs, we explored the interrelationship between security objectives and practices by conducting a canonical analysis based on the data from 354 certified security professionals. We found that for moderately information-sensitive organizations, “Confidentiality” had the highest correlation with information security practices. In these organizations, the security practice contributing most to the security objectives was “Access Control”. For highly information-sensitive organizations, the “Confidentiality”, “Accountability,” and “Integrity” together determine the security practices. In these organizations, the major security practices that impact on security objectives are: “Access Control”, “Organizational Security”, and “Security Policy”. “Access Control” was the only practice contributing to information security objectives in both groups. The items in this dimension focused mainly on technical controls.

About this research paper

What this paper is about

To help practitioners effectively implement security programs, we explored the interrelationship between security objectives and practices by conducting a canonical analysis based on the data from 354 certified security professionals. We found that for moderately information-sensitive organizations, “Confidentiality” had the highest correlation with information security practices. In these organizations, the security practice contributing most to the security objectives was “Access Control”. For highly information-sensitive organizations, the “Confidentiality”, “Accountability,” and “Integrity” together determine the security practices. In these organizations, the major security practices that impact on security objectives are: “Access Control”, “Organizational Security”, and “Security Policy”. “Access Control” was the only practice contributing to information security objectives in both groups. The items in this dimension focused mainly on technical controls.

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

To help practitioners effectively implement security programs, we explored the interrelationship between security objectives and practices by conducting a canonical analysis based on the data from 354 certified security professionals. We found that for moderately information-sensitive organizations, “Confidentiality” had the highest correlation with information security practices. In these organizations, the security practice contributing most to the security objectives was “Access Control”. For highly information-sensitive organizations, the “Confidentiality”, “Accountability,” and “Integrity” together determine the security practices. In these organizations, the major security practices that impact on security objectives are: “Access Control”, “Organizational Security”, and “Security Policy”. “Access Control” was the only practice contributing to information security objectives in both groups. The items in this dimension focused mainly on technical controls.

Key concepts: Certified Information Security Manager, Information security, Information security management, Security information and event management, Standard of Good Practice, Information security audit, Confidentiality, Security management

Related papers

Back to paper searchBrowse research topicsOriginal source
The Interrelationship Between Objectives and Practices in Information Security Management. — Research Paper | ScholarLens