Repository logo
 
No Thumbnail Available
Publication

Definition of information systems security policies

Use this identifier to reference this record.
Name:Description:Size:Format: 
Capa e artigo.pdf8 MBAdobe PDF Download

Advisor(s)

Abstract(s)

Information is considered to be the most critical asset in the business world and the management of the risks associated with information must become a pattern practice within the companies [1]. Therefore, the adoption of an Information Systems Security (ISS) policy for the protection of such an asset makes total sense. Organizations handle increasingly larger amounts of information in technological supports, which makes continuously stricter and broader security controls indispensable. The technological process may work as a catalyst for threats but is not alone enough to ensure the effective security of information. Just as if not more important than reaching the appropriate levels of information security within each organization is being able to maintain them. Having software and hardware which contributes to the security of information is not enough. Organizations must also have a security policy and a good security management so as to firmly anchor the efforts to protect the assets of the information system [2]. In order to better understand the concept of ISS policy, it is convenient to distinguish it from concepts such as norms, directives and procedures. Table 1 shows the differences between these concepts.

Description

Keywords

Information security Definition of security policies Information systems security policies

Citation

Lopes, Isabel Maria; Pereira, João Paulo; Oliveira, P.(2017) - Definition of information systems security policie. In Rocha Á. [et al.] (eds) Recent Advances in Information Systems and Technologies. Springer International Publishing. vol 571, p. 225-234. ISBN 978-3-319-56540-8

Research Projects

Organizational Units

Journal Issue

Publisher

Springer International Publishing

CC License

Altmetrics