A new comprehensive solution to handle information security Governance in organizations

Mounia Zaydi, Bouchaib Nassereddine · 2019

In the last decade, several standards, best practices, and frameworks have been created to help organizations govern the information security in modern organizations in order to optimize processes to achieve business goals. With this in mind, organizations use a variety of mechanisms to ensure that their security architecture is aligned with the organization's business objectives and comply with local standards, rules and regulations in force. Despite the large number of options available, there is considerable confusion over the various methods used by IT managers, and between the various terminologies that suddenly emerged (all at once) in the business world, including information security management (ISM), IT governance (IT-GOV) and information system security governance (ISS-GOV) due to their lack of information compressive Governance approach. This paper, first clarified the main confusions of the different terminologies of this field, and secondly proposes a new in house reference combine the various processes of ITIL V3, ISO 38500 and the security controls of ISO / IEC 27001 which can be used effectively as a complete solution by any organization to govern information security and information technology.

Read the paper · More papers on PaperTik