Traditionally, information security management standards listing generic means of protection have received a lot of attention in the field of information security management. In the background a few information security management‐oriented maturity criteria have been laid down. These criteria can be regarded as the latest promising innovations on the information security checklist‐standard family tree. Whereas information security maturity criteria have so far received inadequate attention in information security circles, software maturity endeavours have been the focus of constructive debate in software engineering circles. Aims to analyze what the alternative maturity criteria for developing secure information systems (IS) and software can learn from these debates on software engineering maturity criteria. First, advances a framework synthesized from the information systems (IS) and software engineering literatures, including six lessons that information security maturity criteria can learn from. Second, pores over the existing information security maturity criteria in the light of this framework. Third, presents, on the basis of results of this analysis, implications for practice and research.
Article navigation
1 December 2002
This article was originally published in
Information Management & Computer Security
Literature Review|
December 01 2002
Towards maturity of information security maturity criteria: six lessons learned from software maturity criteria Available to Purchase
Mikko Siponen
Mikko Siponen
Department of Information Processing Science, University of Oulu, Oulu, Finland
Search for other works by this author on:
Publisher: Emerald Publishing
Online ISSN: 1758-5805
Print ISSN: 0968-5227
© MCB UP Limited
2002
Information Management & Computer Security (2002) 10 (5): 210–224.
Citation
Siponen M (2002), "Towards maturity of information security maturity criteria: six lessons learned from software maturity criteria". Information Management & Computer Security, Vol. 10 No. 5 pp. 210–224, doi: https://doi.org/10.1108/09685220210446560
Download citation file:
520
Views
Suggested Reading
Distributed component software security issues on deploying a secure electronic marketplace
Information Management & Computer Security (March,2000)
A proposed standards‐based approach for representing heterogeneous objects for layered manufacturing
Rapid Prototyping Journal (August,2002)
A framework for access control in workflow systems
Information Management & Computer Security (August,2001)
Deployment of anti‐virus software: a case study
Information Management & Computer Security (March,2003)
Blurring borders, visualizing connections: Aligning information and visual literacy learning outcomes
Reference Services Review (November,2010)
Related Chapters
Exploring Novice Teachers’ Core Competencies
Promoting and Sustaining a Quality Teacher Workforce
Introduction to the Role of External Examining in Higher Education – Challenges and Best Practices
The Role of External Examining in Higher Education: Challenges and Best Practices
FUTURE DIRECTIONS IN THE CEMENT INDUSTRY
Role of Cement Science in Sustainable Development: Proceedings of the International Symposium held at the University of Dundee, Scotland, UK on 3–4 September 2003
Recommended for you
These recommendations are informed by your reading behaviors and indicated interests.
