Get 20M+ Full-Text Papers For Less Than $1.50/day. Start a 14-Day Trial for You or Your Team.

Learn More →

An integrated system theory of information security management

An integrated system theory of information security management With the popularity of electronic commerce, many organizations are facing unprecedented security challenges. Security techniques and management tools have caught a lot of attention from both academia and practitioners. However, there is lacking a theoretical framework for information security management. This paper attempts to integrate security policy theory, risk management theory, control and auditing theory, management system theory and contingency theory in order to build a comprehensive theory of information security management (ISM). This paper suggests that an integrated system theory is useful for understanding information security management, explaining information security management strategies, and predicting management outcomes. This theory may lay a solid theoretical foundation for further empirical research and application. http://www.deepdyve.com/assets/images/DeepDyve-Logo-lg.png Information Management & Computer Security Emerald Publishing

An integrated system theory of information security management

Loading next page...
 
/lp/emerald-publishing/an-integrated-system-theory-of-information-security-management-7FkME2REg0

References (26)

Publisher
Emerald Publishing
Copyright
Copyright © 2003 MCB UP Ltd. All rights reserved.
ISSN
0968-5227
DOI
10.1108/09685220310500153
Publisher site
See Article on Publisher Site

Abstract

With the popularity of electronic commerce, many organizations are facing unprecedented security challenges. Security techniques and management tools have caught a lot of attention from both academia and practitioners. However, there is lacking a theoretical framework for information security management. This paper attempts to integrate security policy theory, risk management theory, control and auditing theory, management system theory and contingency theory in order to build a comprehensive theory of information security management (ISM). This paper suggests that an integrated system theory is useful for understanding information security management, explaining information security management strategies, and predicting management outcomes. This theory may lay a solid theoretical foundation for further empirical research and application.

Journal

Information Management & Computer SecurityEmerald Publishing

Published: Dec 1, 2003

Keywords: Control systems; Risk management; Systems theory; Contingency planning

There are no references for this article.