A process maturity framework of information security policy development life cycle

dc.contributor.advisorFlowerday, Stephenen
dc.contributor.authorTuyikeze, Titeen
dc.date.accessioned2026-08-20T07:23:14Z
dc.date.available2026-08-20T07:23:14Z
dc.date.issued2014-12en
dc.description.abstractInformation security policy development involves more than policy formulation and implementation. Unless organisations explicitly recognise the various steps required in the development of a security policy, they run the risk of developing policies that are poorly thought out, incomplete, redundant and, irrelevant and which will not be fully supported by the users. This study argues that an information security policy has an entire life cycle through which it must pass through during its useful lifetime. A content analysis on information security policy development methods was conducted using secondary sources in the relevant literature. The outcome of the content analysis resulted in the proposal of a framework of information security policy development and implementation. The proposed framework outlines the various steps required in the development, implementation and enforcement of an effective information security policy. A survey of 400 security professionals was conducted in order to evaluate the concepts contained in the framework.This study also emphasises the importance of integrating a security maturity assessment process into the information security policy development life cycle. A key finding of this study is the proposed maturity assessment framework which offers a structured methodology for evaluating the maturity level of an information security policy. The framework presents an integrated and holistic approach to ensure the incremental process maturity of the organisation’s information security policy development process. In addition, organisations using the proposed framework will be able both to determine the current maturity levels of their information security policy development process and also to plan enhancements in the correct sequence.,Thesis (PhD) -- Faculty of Management and Commerce, 2014en
dc.format1 online resource (xiv, 246 leaves)en
dc.formatpdfen
dc.identifier.othervital:66010en
dc.identifier.otherhttp://hdl.handle.net/10353/26797en
dc.identifier.urihttp://hdl.handle.net/20.500.11837/5000
dc.language.isoEnglishen
dc.publisherUniversity of Fort Hareen
dc.publisherFaculty of Management and Commerceen
dc.rightsUniversity of Fort Hareen
dc.rightsAll Rights Reserveden
dc.rightsOpen Accessen
dc.subjectComputer securityen
dc.subjectInformation technologyen
dc.subjectComputer crimesen
dc.subjectGrahamstown (South Africa)en
dc.subjectEastern Cape (South Africa)en
dc.subjectSouth Africaen
dc.subjectHistoryen
dc.titleA process maturity framework of information security policy development life cycleen
dc.typeDoctoral thesesen

Files

Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
vital_66010+SOURCE1+SOURCE1.0.pdf
Size:
2.49 MB
Format:
Adobe Portable Document Format