Abstract

Well-known international security frameworks try to eliminate or mitigate different kinds of risks on the assets covered by their scopes (e.g., people, goods, information, and reputation). To date, to the best of our knowledge, any of these approaches neither provide a comprehensive perspective on security (considered as the merge of physical and logical security) nor consider sustainability as one of the levers for their design, implementation, and execution. This work presents a comprehensive security proposal through a framework that fits to the organizational security needs and contributes to the achievement of the sustainability objectives of an organization by avoiding duplicities and large security gaps from disjointed approaches. The work is supported by a methodology, which is the result of the wide and long work experience of the co-authors on security over the years in different organizations, businesses, and scopes. As it is shown in the theoretical exemplification included in the paper, the proposed framework combines the complementary and joint action of various actors for the protection of assets capable of achieving efforts and dedication efficiency, by merging the aspects of physical and logical security.

Highlights

  • Nowadays, the term security has spread and risen to a big notoriety in our digital society

  • There is no universal definition of security [4], but in this work, the term security aligns with the analysis of [5]

  • This paper proposes a comprehensive security framework that fits the generic protection needs of current organizations and the context that surrounds them, including sustainable development

Read more

Summary

Introduction

Fictitious Business Name (hereafter, FBN) is a theoretical and small consulting company founded in Spain in 2003 by John Doe and Jane Doe. Administration, Europol) or the company itself; Plan and optimize costs and investments necessary to achieve the established objectives; Define lines of coordination and control in the area of security; Know and evaluate, objectively and homogeneously, the maturity of the security at FBN. The implementation of this planned evolution in the security position of FBN towards the proposed CSF goes through reviewing the current security status of the company and analyzing the existing gap in front to the desired situation of CS, for proceeding to adapt the company

Background
Comprehensive Security Framework Proposal
Comprehensive Security Policy
Comprehensive Security Organization
Head of Comprehensive Security
Comprehensive Security Governance
Comprehensive Security Protection
Comprehensive Security Compliance
Comprehensive Security Crisis and Resilience
Comprehensive Security Training and Education
Comprehensive Security Framework Contributions
Comprehensive Security Framework Benefits
Case of Use
Current Security Status
Internal Analysis
External Analysis
New Comprehensive Security Objectives
New Comprehensive Security Organization
Implementation Costs
Findings
Conclusions
Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call