Obstacles to Implementation of Information Security Governance
William W. Lidster, Shawon S.M. Rahman · 2018
Information security leadership has struggled for almost two decades to demonstrate that investment in information security capabilities would return a tangible value to the organization. The efforts to govern and manage security have not resulted in the value statement that has been desired. A critical look at literature reveals that the struggles with governance can be consolidated into three main topics: practitioners do not have guidance on how to implement security governance; security governance models and methods are failing to address the dynamic environment that security works within, and; there lacks a method to measure governance, alignment, and the proposed value that governance brings. This paper examines these issues in the literature, the gaps in the literature, and identifies opportunities to address these gaps.