Configuration Analysis of Key Success Factors of Information Security Management Based on ISO/IEC Standard
Based on the ISO/IEC series of standard documents,the fuzzy set qualitative comparative analy-sis method was applied to explore the synergistic mechanism of multiple factor sets including information security policy,top management,alignment,information security risk assessment,information security awareness,and information security culture that affect the information security management performance.The results show that two types of configuration can improve high information security management per-formance:strong information security awareness and high-level information security culture,high-quality information security policy and complete information security risk assessment.There exists a driving path for information security management which is non-high performance.The organization can carry out effi-cient information security management by integrating internal resources in accordance with the configura-tion results.
information security managementcritical success factorsinformation security standardcon-figurational effect