The ISACA Business Model for Information Security: An Integrative and Innovative Approach
Rolf von Roessing · Vieweg+Teubner eBooks · 2010
In recent years, information security management has matured into a professional discipline that covers both technical and managerial aspects in an organisational environment. Information security is increasingly dependent on business-driven parameters and interfaces to a variety of organisational units and departments. In contrast, common security models and frameworks have remained largely technical. A review of extant models ranging from [LaBe73] to more recent models shows that technical aspects are covered in great detail, while the managerial aspects of security are often neglected.Likewise, the business view on organisational security is frequently at odds with the demands of information security personnel or information technology management. In practice, senior and executive level management remain comparatively distant from technical requirements. As a result, information security is generally regarded as a cost factor rather than a benefit to the organisation. ISACA’s Business Model for Information Security (BMIS) has been developed to address the weaknesses in existing models. It addresses information security primarily from a management perspective, by placing it in the context of a functioning, profit-oriented organisation. The model further outlines approaches and key organisational factors influencing the success or failure of security. The paper presents the BMIS in its entirety, and reflects on the individ-ual components and their significance for information security. It will be shown that the current framework for the BMIS can interface with existing models as well as common control frameworks and international standards. The paper will demonstrate that the complete integration of information security with business is an essential prerequisite to overcoming the technical restrictions and managerial disadvantages often experienced in the past. In relating some of the aspects of BMIS to typical incidents and security violations, the paper will conclude by presenting an outlook on practical BMIS use and addressing typical security risks by means of the BMIS. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.