Policies for Construction of Information Systems' Security Guidelines: Five Approaches

Mikko T. Siponen · Information Security · 2000

Information security research has a bias towards formal and small-scale policies. This research tradition, albeit important, has neglected the non-formal and non-computer oriented security policies. Yet the current classifications concerning security policies do not fully address the issues in security policies within information systems. Firstly, a new classification of (two categories) security policies will be depicted. Secondly, and the main contribution ofthis paper, five approaches to construction of end-user guidelines will be put forth, including the strengths and weaknesses of these approaches.

Read the paper · More papers on PaperTik