'Context, Content, Process' Approach to Align Information Security Investments with Overall Organizational Strategy
Pankaj Pandey

TL;DR
This paper introduces a 'Context, Content, Process' framework to help organizations select and prioritize information security investments aligned with their strategic goals, simplifying decision-making amidst numerous existing models.
Contribution
It proposes a novel framework that guides organizations in evaluating and prioritizing security investments in line with their overall strategy, addressing the complexity of choosing among multiple models.
Findings
Framework effectively aligns security investments with organizational strategy
Simplifies decision-making in selecting security investment models
Enhances prioritization of security controls based on organizational context
Abstract
Today business environment is highly dependent on complex technologies, and information is considered an important asset. Organizations are therefore required to protect their information infrastructure and follow an inclusive risk management approach. One way to achieve this is by aligning the information security investment decisions with respect to organizational strategy. A large number of information security investment models have are in the literature. These models are useful for optimal and cost-effective investments in information security. However, it is extremely challenging for a decision maker to select one or combination of several models to decide on investments in information security controls. We propose a framework to simplify the task of selecting information security investment model(s). The proposed framework follows the 'Context, Content, Process' approach, and…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
