Aligning Security Awareness with Information Systems Security Management



Full text

Journal of Information System Security
Volume 6, Number 1 (2010)
Pages 3654
ISSN 1551-0123
Aggeliki Tsohou — University of the Aegean,, Greece
Maria Karyda — University of the Aegean, Greece
Spyros Kokolakis — University of the Aegean, Greece
Evangelos Kiountouzis — Athens University of Economics and Business, Greece
Information Institute Publishing, Washington DC, USA




This paper explores the way information security awareness connects to the overall information security management framework it serves. To date, the formulation of security awareness initiatives has tended to ignore the important relationship with the overall security management context, and vice versa. In this paper we show that the two processes can be aligned so as to ensure that awareness activities serve the security management strategy and that security management exploits the benefits of an effective awareness effort. To do so, we analyze the processes of security awareness and security management using a process analysis framework and we explore their interactions.The identification of these interactions results in making us able to place awareness in a security management framework instead of viewing it as an isolated security mechanism.




Information Systems Security Management, Security Awareness, Process Analysis, ISO/IEC 27001




