Information Systems Security has recently become an important issue. As this subject crosses three main academic fields and professions -- risk management, auditing and information systems -- three main kinds of problems arise: organization management problems, education problems, and research and development problems. This paper will propose the following:1. A new point in management theory -- that risk management departments are the appropriate location for the "information security risk manager" (ISRM) position with its professional standards.2. A new interdisciplinary course for managing information systems security.3. The establishment of data and knowledge bases for information security risk management to develop expert systems in a way that would fully incorporate currently diverse efforts to modify or correct past directions and to point out future directions.
/lp/association-for-computing-machinery/some-problems-arising-out-of-the-cross-disciplinary-nature-of-vFkkvDoBYl