Abstract

Information Security Management System (ISMS) can be defined as a collection of policies concerned with Information Technology (IT) related risks or Information Security Management (ISM). Majority of ISMS frameworks that have been implemented and adopted by organizations, centre on the use of technology as a medium for securing information systems. However, information security needs to become an organisation-wide and strategic issue, taking it out of the IT domain and aligning it with the corporate governance approach. The aim of this paper is to highlight the available ISMS frameworks, the basic concept of ISMS, the impact of ISMS on computer networks and internet, the chronological developement of ISMS frameworks and IT Security Management/IT Security Organization. These were accomplished through the review of existing literatures on ISMS frameworks. In essence, it was observed that there is need for every organisation to have an information security management system that can adequately provide reasonable assurance and support for IT applications and business processes.

Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call