A framework for the integration of information security and assurance within information systems curricula

David H. Olsen, Richard S. Swart · 2007

The purpose of this dissertation was to develop a framework for integrating information security and assurance content into information systems curriculum. A mixed-methods research design was used to determine the knowledge and skills needed by information security and assurance professionals. This research consisted of two national web-based surveys to determine the needed knowledge and skills for information security, as well as the importance of professional certifications, and to determine what is being taught in information security courses. The surveys were followed by 14 phone-based semi-structured interviews with national leaders in information security and assurance. The research data were analyzed using qualitative means. The triangulation of the survey data and interview data resulted in a detailed list of key knowledge and skills needed by information security and assurance professionals, and a ranking of IT security certifications. The research also determined the source of changes in the IS security' function from the interview data. The implications of the changes to the field and the list of needed skills and abilities were used to analyze the model curricula in computing-related disciplines. A framework was then presented that incorporates the results of this research into the IS 2002 Model Curriculum for Information Systems.

Read the paper · More papers on PaperTik