Business Model for Information Security

[复制链接]
查看11 | 回复1 | 2006-3-26 01:01:42 | 显示全部楼层 |阅读模式
This introduction guide, with case study, is the first document in a series planned around the Business Model for Information Security. Based on the white paper “Systemic Security Management,” developed by the USC Marshall School of Business Institute for Critical Information Infrastructure Protection, this guide provides a starting point for discussion and future development. It defines the core concepts that will evolve into practical aids information security and business unit managers can use to align security program activities with organizational goals and priorities, effectively manage risk, and increase the value of information security program activities to the enterprise.
The Business Model for Information Security does not replace the many sources of security program best practices. It does, however, provide a view of information security program activities within the context the larger enterprise, to integrate the disparate security program components into a holistic system of information protection.
This guide introduces the model and its core concepts to enterprises, particularly to:
Senior executives
Information security managers
Those who have responsibility for managing business risk
Individuals who have responsibility for the design, implementation, monitoring and improvement of an information security management system
回复

使用道具 举报

千问 | 2006-3-26 01:01:42 | 显示全部楼层
感谢分享!
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

主题

0

回帖

4882万

积分

论坛元老

Rank: 8Rank: 8

积分
48824836
热门排行