Framework Processes
Framework Processes
Abstract:
Securing sensitive organizational data has become increasingly vital to organizations. An Information Security
Management System (ISMS) is a systematic approach for establishing, implementing, operating, monitoring, reviewing,
maintaining and improving an organization's information security. Key elements of the operation of an ISMS are ISMS
processes. However, and in spite of its importance, an ISMS process framework with a description of ISMS processes
and their interaction as well as the interaction with other management processes is not available in the literature. Cost
benefit analysis of information security investments regarding single measures protecting information and ISMS
processes are not in the focus of current research, mostly focused on economics. This article aims to fill this research
gap by proposing such an ISMS process framework as the main contribution. It is based on a set of agreed upon ISMS
processes in existing standards like ISO 27000 series, COBIT and ITIL. Within the framework, identified processes are
described and their interaction and interfaces are specified. This framework helps to focus on the operation of the ISMS,
instead of focusing on measures and controls. By this, as a main finding, the systemic character of the ISMS consisting
of processes and the perception of relevant roles of the ISMS is strengthened.
Keywords:
information security; IT security management; ISMS; process framework.
DOI: 10.12821/ijispm040402
Copyr ight © 2016, SciKA. General per missio n t o repu blish in pr int or elect ronic forms, but not for profit , all or part of t his mat er ial is grant ed, provided t hat t he
Int ernat ional Jour nal o f I nfor mat io n S yst ems and Pro ject Manage ment copyr ight notice is given and t hat reference made t o t he publicat ion, t o it s dat e of issue, and t o
t he fact t hat reprint ing pr ivileges were grant ed by per miss io n o f SciKA - Associat ion for Pro mot ion and D isseminat io n o f Scient ific Knowledge.
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 27 ►
A process framework for information security management
1. Introduction
Information security is an integral element of fiduciary duty. The purpose of information security is to protect an
organization’s valuable resources, such as information [1]. Information security is also identified as a subset of
Information Technology (IT) governance [2]. In relevant standards and frameworks as well as in the scientific literature,
the continuously increasing dependency of nearly all organizations on appropriate secure information processing was
stated practically in the last years [3]–[5]. Standards for the management of information security and collections of best
practice measures were developed and established in the literature, e.g. [6]. Important standards for the development
and operation of an ISMS (hereinafter referred to as “ISMS”) are the ISO 27000 series.
Over the last few years, cost benefit discussions have influenced information security practice [7]. The value of
information must justify protection costs. Adjustment and cost-effectiveness are key elements of a successful ISMS [1].
Knowledge of the mission is needed to align the ISMS processes to the organization and its mission [8].
Taking into account that business alignment and cost-effectiveness are important for the successful operation of an
ISMS, research contributions must address both problems by allowing the simplification of the identification of
necessary and appropriate ISMS processes as core elements of every ISMS.
IT and its management are also some of the hot topics for practitioners and researchers alike [9]–[11]. In a scenario, in
which security management has also been pointed out as one of the most important topics in the discipline, there is no
specific process framework for security management which clearly differentiates between ISMS processes and of the
security measures controlled by ISMS-processes. Furthermore, a detailed description of ISMS processes and their
interaction as well as the interaction with other management processes – as already identified in [12] – does not exist.
This problem is further exasperated because information security management is a complex issue [13]. Current research
activities focus on economics and cost benefit analysis of information security investment regarding single measures
protecting information. The ISMS and the ISMS processes themselves are not in the focus of current research [14]–
[16]. So, such a holistic but detailed framework of ISMS core processes as core elements of every ISMS needs to be
developed.
This specific process framework for security management needs to clearly differentiate between ISMS core processes,
supporting processes and management processes, as well as the security measures controlled by ISMS-processes.
Adjustment and cost-effectiveness are key elements of a successful ISMS [1]. A detailed framework of ISMS processes
(input, output, interfaces) and their interaction at an activity level help to ensure an appropriate interaction of the ISMS
processes. To fill this research gap, in this paper a holistic but detailed framework of ISMS core processes as core
elements of every ISMS is proposed.
The remaining of this paper is structured as follows: in section 2 authors give an overview of the most relevant
standards on the topic. In section 3 authors describe the applied research methods and in section 4 authors illustrate the
proposed ISMS process framework and discuss the contained processes. Section 5 gives an overview of the results from
the evaluation of the framework. Section 6 summarizes the main findings and gives an outlook on future research
activities.
2. Background
In relevant standards and frameworks as well as in the literature, the continuous increasing dependency of nearly all
organizations on appropriate secure information processing was stated [17]–[19]. Standards for the management of
information security and collections of best practice measures were developed and established [5], [20]–[22]. Beside
national standards like NIST SP 800 series in the US [23] or the IT security guidelines from the Federal Office for
Information security in Germany [22], the most important standards for the development and operation of an ISMS are
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 28 ►
A process framework for information security management
the ISO 270xx, ITIL and COBIT [24]. The same standards were identified in an ISACA study [25, p. 26] as most used
standards for IT governance and IT management, followed by CMM and CMMI, PRINCE2 and PMBOK.
2.2 ITIL
The IT Infrastructure Library (ITIL), specified in [28]–[33], is a best practice framework for IT service management. IT
service management is the management of all processes that co-operate to ensure the quality of live IT services,
according to the levels of service agreed with the customers [34]. The primary objective of service management is to
ensure that IT services are aligned to the business needs and actively support them [28]. ITIL was developed by the
Central Computing and Telecommunications Agency – today Office of Government Commerce – and is today available
in the third version. ITIL contains five books:
Service strategy [32] – is a guideline for designing and implementing service management as strategic asset.
Service strategy ensures the management of costs and risks of the service portfolio. While not only focusing on
operational efficiency, it also ensures holistic and sustainable services;
Service Design [28] – provides instructions for the development and design of services and processes. Design
principles and methods are presented to transform strategic goals in a portfolio of services and service assets;
Service Transition [33] – contains information about the development and improvement of capabilities regarding
the implementation of new or changed services into production;
Service Operation [31] – is focusing on the operation of IT services regarding efficiency and effectiveness;
Continual Service Improvement [29] – contains instructions for the recurring improvement of design,
implementation and operation of IT services (continual improvement process).
ISO/IEC 20000 [35], [36] is the international standard for service management containing the requirements of a service
management system while ITIL provides a body of knowledge for achieving those requirements [28].
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 29 ►
A process framework for information security management
2.3 COBIT
Control Objectives for Information and related Technology (COBIT), specified in [37]–[40] is a control framework to
help an organization ensure alignment between use of information technology and its business goals [41]. COBIT is
based on five key principles [37]: Meeting stakeholder needs; Covering enterprise end-to-end; Applying a single,
integrated framework; Enabling holistic approach; Separating governance from management.
COBIT also contains a process reference model, generic process capability attributes and a process assessment model
which describes how to execute a capability assessment in an efficient and effective way. COBIT will be analyzed with
the aim to use or adapt the process reference model for the use with ISMS core processes. Furthermore a COBIT 5
Professional Guide for Information Security [40] is provided which focusses on information security and provides more
detailed and more practical guidance.
Mappings and integrations between/of COBIT, ITIL and ISO/IEC27000 series are available [42], [43]. In this article,
the COBIT family is used to identify ISMS core processes and to integrate maturity levels in the ISMS core process
framework.
3. Research methods
According to Susanto et al. [44] the most important and most widely accepted international initiatives for the
development and operation of an ISMS are ISO 27000 series, ITIL [28]–[33] and COBIT [38]. These initiatives are also
relevant in aspects like information and security management [10]. To obtain an agreed basis of ISMS processes of
these standards, multiple process reference models need to be harmonized. To harmonize multiple process reference
models a systematic stepwise approach presented by Baldassarre [45] was used in a mapping study by Haufe et al. [46].
For the analysis of the identified security management standards, an adaptation on the Models and Standards Similarity
Study method by J. A. Calvo-Manzano et al. [47] was used. The method was as follows:
1. Select the models and standards to be analyzed;
2. Choose the reference model – as reference model the ISO 27000 series is chosen because resulting from the
focus of this standard series the widest coverage of ISMS processes is expected;
3. Select the process;
4. Establish a detail level – as all analyzed standards are international standards and are applicable to all
organizations independent of their size, objectives, business model, location, et cetera – the contained
information about ISMS processes are generic. Therefore, a similar level of detail is chosen to analyze the
standards;
5. Create a correspondence template – instead of a detailed correspondence template a process profile template
was created;
6. Identify the similarity among models – the process templates were completed with information obtained from
the standards;
7. Show obtained results.
Also the following basic criteria for ISMS core processes were identified and confirmed in a previous study [48] by the
authors:
Criteria 1 – Regularity – interrelated and interacting tasks are repeated on a regular basis;
Criteria 2 – Transformation – inputs are transformed into outputs;
Criteria 3 – Operationally – process is carried out while operating the ISMS;
Criteria 4 – Accountability/responsibility – information security officer is the process owner or process manager
and the process is a core competency of the ISMS;
Criteria 5 – Value generating – delivers apparent and direct value to the stakeholder.
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 30 ►
A process framework for information security management
4. Process Framework
As a result of the mapping study the following processes were identified as ISMS processes:
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 31 ►
A process framework for information security management
ISMS processes and their interaction at a high level basis are shown in Fig. 1. ISMS process framework. Some
interfaces are not illustrated to enable a better readability of Fig. 1. ISMS process framework: Every ISMS process
provides input for the documentation and records control process; The ISMS planning as well as the configuration
management process provide input for every ISMS process.
Management
Documentation and
ISMS core processes processes
records control process ISMS planning
(documentation of the process (provides
output of the processes) input for the ISMS
processes)
Changed requirements, list of requirements
Applicable requirements
Requests for Changes and change results/status
Reports regarding resource usage for ISMS controls
Results of changes
Proposed changes and evaluated risks of proposed changes Request for changes
Requests for Changes
Resource usage reports Information Information
Resource Estimation of security change security
management necessary Requests for Changes
Requirements resources management governance
Customer Applicable process
requirements
management to implement process process
requirements
process controls
Selected controls Requests for Changes
Support processes
Configuration
management process
The ISMS planning process is the process of ISMS specification and design from inception to the production of
implementation plans. Documentation and records control process is the process to identify, create, update and
control information determined to be necessary for the effectiveness of the ISMS.
Key to reach the ISMS objectives is an up-to-date understanding of the needs and expectations of interested parties
relevant to information security and the ISMS. This is realized within the requirements management process, which
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 32 ►
A process framework for information security management
provides identified legal, statutory, regulatory and contractual requirements for the risk assessment process, the internal
audit process and the process to control outsourced processes.
In the risk assessment process, risks are identified, analyzed and evaluated. The output of this process are documented
and evaluated risks in a list of prioritized risks including threats, vulnerabilities and risk owners, consequences and
business impact, likelihood and comparison against risk criteria as well as evaluated risks of proposed changes, which
are input for the communication process and the information security risk treatment process.
In the information security risk treatment process risk treatment options including control objectives and controls are
identified and selected. Output of this process are list with selected controls and control objectives, a risk treatment plan
including acceptance of residual risks, a control implementation plan and requests for changes to information security
change management process, which are used as input in various ISMS processes.
Resources needed to implement the controls as well as to run the ISMS processes are identified, allocated and
monitored in the resource management process. Output of the resource management process are planned/documented
resources to implement and run selected controls, categorization of controls regarding who funds the control, planned
and documented resources to run the ISMS core processes, reports regarding resource usage of ISMS core processes,
and for the information security customer relationship management process: reports on resource usage. The
implementation of controls always results in changes, which can be managed within a general change management
process of the implementing organization or – if the change focuses on an ISMS element – within the information
security change management process. The information security change management process is the process to control
changes of ISMS elements and review the consequences of unintended changes. This process only focusses on change
management of the ISMS. Output of this process are necessary changes (for documentation and records control
process), proposed and necessary changes as well as results of changes (for and from risk assessment process), initiation
of risk assessment when significant changes are proposed or occur and the results of changes to information security
incident management process, as they were initiated by that process.
The information security incident management process is for detecting, reporting, assessing, responding to, dealing
with and learning from information security incidents. Output of this process are identified incidents which are used in
various ISMS processes including the information security change management process and the process to ensure
necessary awareness.
In the information security awareness process an information security awareness, training and education program is
developed and implemented to ensure that all personnel receive the necessary security training and/or education.
As services are outsourced, these services need to be determined and controlled, which is realized within the process to
control outsourced services.
The performance evaluation process contains monitoring, measurement, analysis and evaluation of two main criteria.
First, the performance of the security controls and second the performance of the ISMS processes. Performance
measurement differs from performance audit (internal audit) regarding effectiveness and efficiency of the ISMS and
implemented controls which is performed independently within the internal audit process.
Results from the performance evaluation process, the internal audit process as well as results from the service provider
audits from the process to control outsourced services are used to improve effectiveness, efficiency, suitability and
adequacy of the ISMS and the controls. This is realized within the information security improvement process.
Results of nearly all ISMS processes are centrally communicated within the communication process to stakeholders
outside the ISMS. This includes the communication of risks and information security management reports. Those
reports as well as identified requirements are input for the information security governance process, which ensures an
alignment of the ISMS with the objectives and needs of the governing stakeholders.
Beside the information security governance process, which forms the interface between the ISMS and its stakeholders,
the operational management of the customer satisfaction level as well as the continuous demonstration of the added
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 33 ►
A process framework for information security management
value of investments in information security need to be realized. This is done within the information security
customer relationship management process.
The ISMS processes are discussed in more detail in the following subsections.
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 34 ►
A process framework for information security management
ISMS and should be applied to the ongoing operation of an ISMS [51, p. 3]. The information security risk assessment
process is a source of value for the top management while it provides a set of documented risks as well as a documented
evaluation of those risks to help the decision making.
Again, this process is also part of the service management system [35, pp. 18–19]. One more time, synergy effects
appear when the integration of ISMS and service management is made possible.
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 35 ►
A process framework for information security management
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 36 ►
A process framework for information security management
for the information security officer, because he or she is responsible to proof an appropriate ISMS to the top
management. Furthermore, well managed documents with the use of the documentation and records control and the
communication process, enable the employees to have access to relevant ISMS documents which will lead to a higher
security level.
This process is also part of the service management system. Again, synergy effects appear when the integration of
ISMS and service management is made possible.
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 37 ►
A process framework for information security management
The process to control outsourced services is focused on ensuring information security and it is a specialized part of the
broader management of providers. The management of providers also includes quality- and performance management
(monitoring of key performance indicators), SLA-management and contract management as defined in the supplier
management process of the ISO/IEC 20000. Due to the specialization of the process to control outsourced services, this
process is carried out while operating the ISMS and clearly within the core competency of the ISMS.
Like the general management of information security, this process ensures an adequate level of information security and
is, therefore, value generating.
This process is also part of the service management system [35, pp. 18–19]. Again, synergy effects appear when the
integration of ISMS and service management is made possible.
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 38 ►
A process framework for information security management
Results of this process like audit and management reports are a direct value for the top management (stakeholders) as
they support decision making of the top management [49, p. 63] regarding ISMS-related decisions and improvement of
the ISMS [53, p. vii]
This process is also part of the service management system [35, pp. 18–19]. Again, synergy effects appear when the
integration of ISMS and service management is made possible.
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 39 ►
A process framework for information security management
5. Evaluation
To verify or dismiss the identified ISMS core processes or add missing ISMS core processes, the authors of this article
conducted a study [48]. In this study, 90 experts were asked to name ISMS core processes in form of a questionnaire. A
panel of 90 German experts in the field of information security was selected, from which 75 experts answered the
questionnaire. Roles of the experts were: 53 Information security officers/managers (23 working for private companies;
30 working for public administration); 8 consultants for information security (8 working for private companies); 14
auditors for information security (3 working for public administration; 8 working for private companies).
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 40 ►
A process framework for information security management
The set of possible ISMS core processes was given as shown in Table 2. Results of the study to identify ISMS core
processes.
Named process
ISMS planning process
Information security risk assessment process
Information security risk treatment process
Resource management process
Process to assure necessary awareness and competence
Communication process
Documentation control process
Requirements management process
Information security change management process
Process to control outsourced processes
Performance evaluation process
Internal audit process
Information security improvement process
Information security governance process
Information security incident management process
Service level management process
Service reporting process
Service continuity and availability management process
Budgeting and accounting for services process
Capacity management process
Business relationship management process
Supplier management process
Incident and service request management process
Problem management process
Configuration management process
Change management process
Release and deployment management process
Information security customer relationship management process
The detailed results of the study are described in Haufe et al. [48] and mainly confirmed the set of ISMS core processes
proposed in this work.
The ISMS core process framework have been implemented and are operational in a medium-sized government
organization as a pilot project. The first results of the pilot application are:
An unmodified application of the ISMS process framework is not suitable. ISMS processes need to be tailored to
the specific needs of the organization, but are of great value as a starting point. Starting with a holistic ISMS
process framework results in focusing on a process perspective rather than a measure perspective. This is
especially helpful because risks of a measurement driven approach like the understanding of information security
as a one-time project are avoided and replaced by a process oriented view which better fulfills the requirement of
operating an ISMS. A holistic ISMS process framework as a starting point also prevents the implementing
organization from researching the standards regarding ISMS processes, as they are already provided;
Beside the modification of the ISMS processes, processes differ in the implemented maturity level. Especially
the process to control outsourced services and the information security incident management process need to be
implemented at a high maturity level in the piloting organization due to a significant dependability on the
provided services;
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 41 ►
A process framework for information security management
Some processes are not necessary at maturity levels of “defined” or lower. Examples are internal audit process,
performance evaluation process, information security improvement processes;
The process "Documents and records control process" should be divided in "Security policy management
process" (ISMS core process) from Veiga and Eloff [50] and "Records control process" (Support process).
To sum up the initial evaluation results, implementing the proposed ISMS process framework has the following
advantages compared to the traditional measurement or control-objective-driven approach:
Efficiency – the implementing organization does not need to research possible ISMS processes in the ISO
standards, as they are provided with the framework;
Operational focus – by implementing the ISMS process framework the focus is shifted from control objectives to
a process oriented view, which better enables and supports an operation of an ISMS.
The pilot implementation of the proposed ISMS process framework proved that a process-oriented view of the ISMS
can help focusing on the operation of an ISMS and improve the efficiency while planning such processes. By this, as a
main finding, the systemic character of the ISMS consisting of processes and the perception of relevant roles of the
ISMS is strengthened.
The pilot implementation also showed that some improvements of the framework need to be done and that an
unadjusted implementation of the framework will not be sufficient. Given that the future work will consist of three
steps:
Step 2: Development of a method to adjust and make costs for operating the ISMS core processes transparent.
Transparency of information security costs could be further improved by tailoring the maturity level of ISMS processes
to the requirements of the organization. Considering limited resources as well as ensuring an efficient use of those
resources, not every ISMS process should be established and operated at the same level of maturity [25, p. 8]. By
considering a maturity level model for ISMS processes combined with an approach for the determination of the
necessary maturity level, the appropriateness of an ISMS can be made transparent as well as unnecessary costs of
information governance can be avoided.
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 42 ►
A process framework for information security management
References
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 43 ►
A process framework for information security management
[21] International Organization for Standardisation and International Electrotechnical Commission, ISO/IEC
27002:2013. Geneva, 2013.
[22] German Federal Office for Information Security, IT-Grundschutz Catalogues, 13th ed. Bonn, 2013.
[23] U.S. Department of Commerce - National Institute of Standards and Technology, NIST Special Publication 800
series. Gaithersburg.
[24] M. Stoll, “An Information Security Model for Implementing the New ISO 27001,” Handbook of Research on
Emerging Developments in Data Privacy, p. 216, 2014.
[25] Information Systems Audit and Control Association, IT-Governance and Process Maturity. Rolling Meadows,
2008.
[26] W. Boehmer, “Appraisal of the Effectiveness and Efficiency of an Information Security Management System
Based on ISO 27001,” SECURWARE, vol. 8, pp. 224–231, 2008.
[27] J. Brenner, “ISO 27001: Risk management and compliance,” Risk Management Magazine, vol. 54, no. 1, p. 24,
2007.
[28] Office of Government Commerce, ITIL v3 Service Design. London, 2007.
[29] Office of Government Commerce, ITIL v3 Service Improvement. London, 2007.
[30] Office of Government Commerce, ITIL v3 Service Lifecycle. London, 2007.
[31] Office of Government Commerce, ITIL v3 Service Operation. London, 2007.
[32] Office of Government Commerce, ITIL v3 Service Strategy. London, 2007.
[33] Office of Government Commerce, ITIL v3 Service Transition. London, 2007.
[34] V. H. Publishing, IT service management: an introduction. Van Haren Publishing, 2007.
[35] International Organization for Standardisation and International Electrotechnical Commission, ISO/IEC 20000-
1:2011. Geneva, 2011.
[36] International Organization for Standardisation and International Electrotechnical Commission, ISO/IEC 20000-
2:2012. Geneva, 2012.
[37] Information Systems Audit and Control Association, COBIT 5 A Business Framework for the Governance and
Management of Enterprise IT. Rolling Meadows.
[38] Information Systems Audit and Control Association, COBIT 5 Enabling Processes. Rolling Meadows.
[39] Information Systems Audit and Control Association, COBIT 5 Process Assessment Model (PAM): Using COBIT 5.
Rolling Meadows.
[40] Information Systems Audit and Control Association, COBIT 5 for Information Security. Rolling Meadows.
[41] G. Ridley, J. Young and P. Carroll, “COBIT and its Utilization: A framework from the literature,” in System
Sciences, 2004. Proceedings of the 37th Annual Hawaii International Conference on System Sciences, 2004, p. 8.
[42] S. Sahibudin, M. Sharifi and M. Ayat, “Combining ITIL, COBIT and ISO/IEC 27002 in order to design a
comprehensive IT framework in organizations,” in Modeling & Simulation, 2008. AICMS 08. Second Asia International
Conference on, 2008, pp. 749–753.
[43] B. Von Solms, “Information Security governance: COBIT or ISO 17799 or both?,” Computers & Security, vol. 24,
no. 2, pp. 99–104, 2005.
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 44 ►
A process framework for information security management
[44] H. Susanto12, M. N. Almunawar and Y. C. Tuan, “Information security management system standards: A
comparative study of the big five,” International Journal of Electrical Computer Sciences, vol. 11, no. 5, pp. 23–29,
2011.
[45] C. Pardo, F. J. Pino, F. García, M. Piattini and M. T. Baldassarre, “A process for driving the harmonization of
models,” in Proceedings of the 11th International Conference on Product Focused Software, 2010, pp. 51–54.
[46] K. Haufe, R. Colomo-Palacios, S. Dzombeta, K. Brandis and V. Stantchev, “Security Management Standards: A
mapping,” presented at the Conference on ENTERprise Information Systems / International Conference on Project
MANagement / Conference on Health and Social Care Information Systems and Technologies, CENTERIS / ProjMAN
/ HCist, Porto, Portugal, 2016.
[47] J. A. Calvo-Manzano, G. Cuevas and M. Muñoz, “Project Management Similarity Study: Experiment on Project
Planning Practices Based on CMMI-Dev v1.2,” in EuroSPI 2008 - Proceedings, Dublin, 2008, p. 11.
[48] K. Haufe, R. Colomo-Palacios, S. Dzombeta, K. Brandis and V. Stantchev, “ISMS core processes: A study,”
presented at the Conference on ENTERprise Information Systems / International Conference on Project MANagement /
Conference on Health and Social Care Information Systems and Technologies, CENTERIS / ProjMAN / HCist, Porto,
Portugal, 2016.
[49] International Organization for Standardisation and International Electrotechnical Commission, ISO/IEC
27003:2010. Geneva, 2010.
[50] A. D. Veiga and J. H. Eloff, “An information security governance framework,” Information Systems Management,
vol. 24, no. 4, pp. 361–372, 2007.
[51] International Organization for Standardisation and International Electrotechnical Commission, ISO/IEC
27005:2011. Geneva, 2011.
[52] D.-K. M. Nofer, O. Hinz, J. Muntermann and H. Rossnagel, “The Economic Impact of Privacy Violations and
Security Breaches,” Business & Information Systems Engineering, vol. 6, no. 6, pp. 339–348, 2014.
[53] International Organization for Standardisation and International Electrotechnical Commission, ISO/IEC
27004:2010. Geneva, 2010.
[54] International Organization for Standardisation and International Electrotechnical Commission, ISO/IEC
27000:2014. Geneva, 2014.
[55] J. D. Howard and T. A. Longstaff, “A common language for computer security incidents,” Sandia National
Laboratories, 1998.
[56] E. Humphreys, “Information security management standards: Compliance, governance and risk management,”
information security technical report, vol. 13, no. 4, pp. 247–255, 2008.
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 45 ►
A process framework for information security management
Biographical notes
Knut Haufe
Knut Haufe is a PhD candidate at the Universidad Carlos III de Madrid. He is also Lead Expert for
information security management systems at PERSICON corporation, Germany and has more than
ten years of experience as project manager for information security, audits and audit-preliminary
consulting related to the German IT baseline security manual from the BSI (Federal Office of
Information Security) and ISO 27001. Knut Haufe holds a Master in Commercial Law (LL.M. Com.)
from the University of Kaiserslautern, Germany and a Diplom in Wirtschaftsinformatik (business
informatics) from the Technical University of Ilmenau, Germany. He is also a member of the
Standards Committee on Information Technology and Applications (NIA) 043-01-27-01 of the DIN
(German Institute for Standardization which represents German interests within ISO, the
International Organization for Standardization) which works on information security management
system standards.
[Link]/khaufe@[Link]
Ricardo Colomo-Palacios
Full Professor at the Computer Science Department of the Østfold University College, Norway.
Formerly he worked at Universidad Carlos III de Madrid, Spain. His research interests include
applied research in Information Systems, IT project management and people in IT projects among
others. He received his PhD in Computer Science from the Universidad Politécnica of Madrid
(2005). He also holds a MBA from the Instituto de Empresa (2002). He has been working as
Software Engineer, Project Manager and Software Engineering Consultant in several companies
including Spanish IT leader INDRA. He is also an Editorial Board Member and Associate Editor for
several international journals and conferences and Editor in Chief of International Journal of Human
Capital and Information Technology Professionals. He has published more than two hundred works
in journals, books and conferences.
[Link]/[Link]-palacios@[Link]
Srdan Dzombeta
Srdan Dzombeta is a business graduate and Master in Commercial Law (LL.M. Com.). He studied at
the Technical University Berlin, the University of California in Los Angeles and Saarland
University. Srdan Dzombeta is the partner with responsibility for governance and compliance and
deals with implementing the propriety requirements for relevant processes and procedures when
using information technology. Srdan Dzombeta gained experience in the use of national and
international legal norms and recognized standards particularly while working for several years with
a leading international accounting firm. For example, he was manager for planning and executing
various consulting and auditing projects in the fields of telecommunication, finance, post and
transport/logistics together with technology/IT outsourcing.
[Link]/sdzombeta@[Link]
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 46 ►
A process framework for information security management
Knud Brandis
Knud Brandis studied law at the University of Potsdam and acquired his Master of Business
Administration (MBA) in Financial Management from the University of Wales (UK) in 2005. As a
Partner at PERSION, he is responsible for the information security and risk management department.
He is primarily engaged with the management- and control aspects. Among other positions Knud
Brandis held, he gained his experience in the implementation of national and international standards
through his long engagement as a senior audit manager for a leading international accounting
company in New York. He is co-author of the IT-baseline security catalogue (previously IT-security
handbook) of the German Federal Office for Information Security. Knud Brandis is also lecturer for
the Master course “information security management” at Brandenburg college, for “IT-Service
management according to ITIL” at the dual education college in Villingen-Schwenningen as well as
for “Consulting” at the Berlin School of Economics and Law.
[Link]/kbrandis@[Link]
Vladimir Stantchev
Vladimir Stantchev is the executive director of the Institute of Information Systems at SRH
University Berlin where he is a research professor. He is also a professor at the University of
Granada, Spain and an affiliated senior researcher with the Networking Group at the International
Computer Science Institute (ICSI) in Berkeley, California, USA. Vladimir Stantchev studied law at
Sofia University (Sofia, Bulgaria) and also earned his master’s degree in computer science from the
Humboldt-University in Berlin, Germany. He received his PhD (Dr. rer. nat.) in the area of system
architectures from the EECS department of the Berlin Institute of Technology (TU Berlin). His
major research interests are in the areas of IT-Governance, Cloud Computing architectures, IT
strategy, as well as methods for service and software engineering.
[Link]/[Link]@[Link]
International Journal of Information Systems and Project Management, Vol. 4, No. 4, 2016, 27-47
◄ 47 ►