F. Business Model for Information Security (BMIS) Flashcards
What is Business Model for Information Security (BMIS)
A guide developed by ISACA for business-aligned, risk based security governance.
What does the use of BMIS do
It helps security leadership ensure that the organization’s security program continues to address emerging threats, developing regulations, and changing business needs.
element of IT model
People, process, technology
elements of BMIS model
It’s a three-dimensional, three-sided pyramid which includes element of IT model (people, process, technology) and a fourth element i.e. organization
Element of organization
Culture, governing, Architecture
What is the apex (highest) element of the BMIS pyramid
The organization
How are the elements of BMIS model connected
By dynamic interconnections which are culture, governing, architecture, emergence, enabling and support, and human factors
Organization as element of BMIS model
Organization is viewed as a network of people interacting using processes to channel this interaction.
Organization includes permanent staff, temporary staff, contractors, people of outsourced organizations, third parties that play a role in helping the organization achieve its objectives
Defining the people element in the BMIS
They represent all of the people in an organization, including people in outsources organizations that do business with the entity.
Defining the process element in the BMIS
It’s the formal structure of all defined activities,
Process defines practices and procedures that describe how activities are to be carried out.
What is an effective process per ISACA’s Risk IT framework?
A reliable and repetitive collection of activities and controls to perform a certain task.
Defining the Technology element in the BMIS
It’s represents all of the systems, application, and tools used. It’s a powerful enabler of an organization’s processes and its strategic objectives.
Defining culture in the dynamic interconnection of the organization
Culture is a pattern of behaviors, beliefs, assumptions, and ways of doing things.
Culture connects the organization and people elements.
Why is culture the most critical factors in the success or failure of an information security program
Because culture reflects the attitudes, habits, and customs adopted by the people in the organization. Culture cannot be legislated or controlled directly.
Civil culture in which organization resides
It plays a large role in sharping role the organization’s culture.
It makes it difficult for organization that have many global or regional location to establish a single culture.