A generic framework for information security policy development
Title | A generic framework for information security policy development |
Publication Type | Conference Paper |
Year of Publication | 2017 |
Authors | Ismail, W. B. W., Widyarto, S., Ahmad, R. A. T. R., Ghani, K. A. |
Conference Name | 2017 4th International Conference on Electrical Engineering, Computer Science and Informatics (EECSI) |
ISBN Number | 978-1-5386-0549-3 |
Keywords | Education, further education, generic framework, higher education institutions, improper development process, Information security, information security policies, information security policy, information security policy development process, Law, maintenance engineering, Organizations, pubcrawl, replicated policy, risk management, security of data, security policies, security policy content, security policy development |
Abstract | Information security policies are not easy to create unless organizations explicitly recognize the various steps required in the development process of an information security policy, especially in institutions of higher education that use enormous amounts of IT. An improper development process or a copied security policy content from another organization might also fail to execute an effective job. The execution could be aimed at addressing an issue such as the non-compliance to applicable rules and regulations even if the replicated policy is properly developed, referenced, cited in laws or regulations and interpreted correctly. A generic framework was proposed to improve and establish the development process of security policies in institutions of higher education. The content analysis and cross-case analysis methods were used in this study in order to gain a thorough understanding of the information security policy development process in institutions of higher education. |
URL | https://ieeexplore.ieee.org/document/8239132/ |
DOI | 10.1109/EECSI.2017.8239132 |
Citation Key | ismail_generic_2017 |
- Law
- security policy development
- security policy content
- security policies
- security of data
- risk management
- replicated policy
- pubcrawl
- Organizations
- maintenance engineering
- education
- information security policy development process
- information security policy
- information security policies
- information security
- improper development process
- higher education institutions
- generic framework
- further education