Towards maturity of information security maturity criteria: six lessons learned from software maturity criteria
Information Management & Computer Security
ISSN: 0968-5227
Article publication date: 1 December 2002
Abstract
Traditionally, information security management standards listing generic means of protection have received a lot of attention in the field of information security management. In the background a few information security management‐oriented maturity criteria have been laid down. These criteria can be regarded as the latest promising innovations on the information security checklist‐standard family tree. Whereas information security maturity criteria have so far received inadequate attention in information security circles, software maturity endeavours have been the focus of constructive debate in software engineering circles. Aims to analyze what the alternative maturity criteria for developing secure information systems (IS) and software can learn from these debates on software engineering maturity criteria. First, advances a framework synthesized from the information systems (IS) and software engineering literatures, including six lessons that information security maturity criteria can learn from. Second, pores over the existing information security maturity criteria in the light of this framework. Third, presents, on the basis of results of this analysis, implications for practice and research.
Keywords
Citation
Siponen, M. (2002), "Towards maturity of information security maturity criteria: six lessons learned from software maturity criteria", Information Management & Computer Security, Vol. 10 No. 5, pp. 210-224. https://doi.org/10.1108/09685220210446560
Publisher
:MCB UP Ltd
Copyright © 2002, MCB UP Limited