The Center for Education and Research in Information Assurance and Security (CERIAS)

The Center for Education and Research in
Information Assurance and Security (CERIAS)

A policy framework for information security

Download

Download PDF Document
PDF

Author

Jackie Rees, Shubho Bandyopadhyay, Eugene H. Spafford

Tech report number

CERIAS TR 2003-52

Entry type

article

Abstract

As organizations increasingly rely on information systems as the primary way to conduct operations, keeping such systems secure requires increasing emphasis. This paper provides information security professionals and top management a framework through which usable security strategy and policy for applications can be created and maintained in line with the standard information technology life cycle. This framework, the Policy Framework for Interpreting Risk in E-Business Security (PFIRES), was initially developed for e-commerce activities and has since been generalized to handle security policy for all types of organizations engaged in computing and Internet operations. This framework offers a possible starting point for understanding a security policy's impact on an organization, and is intended to guide organizations in developing, implementing, and maintaining security policy.

Download

PDF

Date

2003 – 07

Journal

Communications of the ACM

Key alpha

Spafford

Number

7

Pages

101-106

Volume

46

Publication Date

2003-07-01

BibTex-formatted data

To refer to this entry, you may select and copy the text below and paste it into your BibTex document. Note that the text may not contain all macros that BibTex supports.