کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
456366 695701 2016 15 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Information security policy development and implementation: The what, how and who
ترجمه فارسی عنوان
توسعه و اجرای سیاست های امنیتی اطلاعات: چه، چه و چه کسی
کلمات کلیدی
توسعه سیاست امنیتی، اجرای سیاست امنیتی، چرخه حیات سیاست امنیتی، مدیریت سیاست امنیتی، ارزیابی ریسک
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
چکیده انگلیسی

The development of an information security policy involves more than mere policy formulation and implementation. Unless organisations explicitly recognise the various steps required in the development of a security policy, they run the risk of developing a policy that is poorly thought out, incomplete, redundant and irrelevant, and which will not be fully supported by the users. This paper argues that an information security policy has an entire life cycle through which it must pass during its useful lifetime. A formal content analysis of information security policy development methods was conducted using secondary sources. Based on the results of the content analysis, a conceptual framework was subsequently developed. The proposed framework outlines the various constructs required in the development and implementation of an effective information security policy. In the course of this study, a survey of 310 security professionals was conducted in order to validate and refine the concepts contained in the key component of the framework: the ISPDLC.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Computers & Security - Volume 61, August 2016, Pages 169–183
نویسندگان
, ,