Information has become a key resource and even the lifeblood of many organizations. The successful management of information security in an organization is vital to its survival and success. This paper answers the difficult problems that organizations...
Information has become a key resource and even the lifeblood of many organizations. The successful management of information security in an organization is vital to its survival and success. This paper answers the difficult problems that organizations easily face in business environments when they try to solve information security issues by suggesting the integrated methodology for security engineering.Contributions of this paper are summarized as following. The first is the integrated framework which can be used by later researchers to coordinate earlier researches. The second is the process model which supply a main body that the other tools and methods may be linked. The last one is a suggestion of components that can be used in various environments: component for the strategic planning of information security; component for the evaluation of information security systems; component for the economic justifications of investment on information security systems; component for the selection and introduction of package-based security controls.This paper could be believed to be the first attempt to suggest integrated methodology which supports entire life cycle of planning, implementations, and operations of information security systems. The information security is not only related with a field of study of computer science or industrial engineering but also related with various fields of study of law, administration, psychology, architecture, mathematics, and so on. So, further researches on integrated methodology for security engineering of information security systems should be more broadly related with other fields of study.