Observations on Practical Information Security Issuesand Life Cycle Management in IT Systems- a Case Study
Margaretha Eriksson · 2010
Abstract. This paper presents three case studies related to practical information security issues during the Life Cycle of IT systems in (1) a big, global organisation, (2) a medium sized governmental agency, and (3) a small sales and production enterprise. The maturity of the processes used during systems development, as well as the organisation are taken into consideration, and methods of communication of information security, follow-up and feedback is described. Security related processes and procedures, or the lack thereof, are described and their effect discussed. Efficient communication of the security policy, fast feedback on actions and follow-up on security related procedures seems to increase the level of information security and can be expressed in terms of the Quality of Service delivered from the organisation to its customers or clients.