Modern society depends on information technology in nearly every facet of human activity including, finance, transportation, education, government, and defense. Organizations are exposed to various kinds of risks, including information technology risks. Several standards, best practices, and frameworks have been created to help organizations manage these risks. The purpose of this research work is to highlight the challenges facing enterprises in their efforts to properly manage information security risks when adopting international standards and frameworks. To assist in selecting the best framework to use in risk management, the article presents an overview of the most popular and widely used standards and identifies selection criteria. It suggests an approach to proper implementation as well. A set of recommendations is put forward with further research opportunities on the subject.
Information security risk management security frameworks security standards security management
Primary Language | English |
---|---|
Journal Section | Articles |
Authors | |
Publication Date | June 28, 2013 |
Submission Date | January 30, 2016 |
Published in Issue | Year 2013 Volume: 2 Issue: 2 |