A Methodology for Managing Information-Based Risk

Holmes E. Miller, Kurt J. Engemann · Information Resources Management Journal · 1996

Organizations often think of information security as a technological issue best left to technical specialists. While many security strategies undoubtedly rely on hardware and software solutions, the management processes surrounding security and the ongoing commitment of business and operations managers to security issues are no less important. In this paper we discuss a three-phase methodology for managing information-based risks, and present results of how a large money center bank implemented the methodology at numerous locations around the world. Our discussion focuses on the methodology, the implementation process, the results, and how similar efforts can be used in designing management processes to improve the security of information assets.Request access from your librarian to read this article's full text.

Read the paper · More papers on PaperTik