National information security policy and its implementation: A case study in Taiwan
Cheng-Yuan Ku,
Yi-Wen Chang and
David C. Yen
Telecommunications Policy, 2009, vol. 33, issue 7, 371-384
Abstract:
Cyberspace is no longer safe. From business organizations to countries, the requirements of information security and assurance have become one of the most important functions to ensure continued operations. The goal of this study is twofold. First, we introduce the information security policy of the Taiwanese government and its current status. Then we present a successful example of governmental institute that self-adopted the information security management system (ISMS), British Standard 7799 (ISO27001). The results of this research indicate that past successful experiences, availability of documents, cost constraints, organization learning and organizational culture are important motivations of self-implementation of ISMS. Past experience of other standards, level of documentation and standardization, degree of understanding the clauses, procedures of risk management, top management support, culture of organization, existing auditing infrastructure, awareness of information security, education and compatibility with the existing procedures are the key factors of successful self-implementation of ISMS.
Keywords: Information; security; National; information; security; policy; Information; security; management; system; (ISMS); BS7799; ISO27001 (search for similar items in EconPapers)
Date: 2009
References: Add references at CitEc
Citations: View citations in EconPapers (2)
Downloads: (external link)
http://www.sciencedirect.com/science/article/pii/S0308596109000263
Full text for ScienceDirect subscribers only
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:eee:telpol:v:33:y:2009:i:7:p:371-384
Ordering information: This journal article can be ordered from
http://www.elsevier.com/wps/find/journaldescription.cws_home/30471/bibliographic
http://www.elsevier. ... /30471/bibliographic
Access Statistics for this article
Telecommunications Policy is currently edited by Erik Bohlin
More articles in Telecommunications Policy from Elsevier
Bibliographic data for series maintained by Catherine Liu ().