Management's role in information security in a cyber economy

被引:72
作者
Dutta, A [1 ]
McCrohan, K [1 ]
机构
[1] George Mason Univ, Fairfax, VA 22030 USA
关键词
D O I
10.2307/41166154
中图分类号
F [经济];
学科分类号
02 ;
摘要
Information security is not a technical issue; it is a management issue. It rests on three cornerstones-critical infrastructures, organization, and technology. While critical infrastructures are beyond the direct control of the organization, balancing them is a critical component of corporate governance. Total security is neither technically feasible nor operationally practicable. Therefore the organization must determine what information assets must be protected and the degree of protection to be provided for them. As Internet-based commerce diffuses through society, there will be decreasing tolerance on the part of customers for losses stemming from perceived or actual cyber vulnerabilities. Only senior management can initiate the plans and policies that address the different aspects of security in a balanced and integrated manner. Leaving security primarily to the IT function will strengthen just one of the cornerstones-namely, technology-and will not yield the intended results. Security lapses are management failures more than technical failures. This article presents an organizational security approach that senior managers can use as a roadmap to initiate security plans and policies and audit their implementation.
引用
收藏
页码:67 / +
页数:22
相关论文
共 14 条
[1]  
[Anonymous], CYBER THREATS INFORM
[2]  
BRYCE R, 2001, INTERACTIVE WEE 0819
[3]  
*COMP SEC I, 2002, COMP SEC ISS TRENDS
[4]  
DISABATINO J, 2001, COMPUTER WORLD 1207
[5]  
GRONJE G, 2001, CHOOSING BEST FIREWA
[6]  
LEMOS R, 2001, REPORT BUSINESS FAIL
[7]  
NDIA, 2000, COMP NETW DEF IND PE
[8]  
Power R., 2000, CURRENT FUTURE DANGE
[9]  
RODGER W, 2002, SECURITYFOCUS 0210
[10]  
ROSENCRANCE L, 2002, SECURITY FOCUS 0108