Using the Security Management Framework
The business organisation model, shown above, can be overlaid onto the models subsequently described in this paper to describe the way in which security relates to an organisation.
The security management framework can be used to describe the different perspectives that people have on security and relate the security to the business organisation. The balance between Centralised, Decentralised and Federated models would relate to the emphasis on the Group vs. the Business Divisions. For example, the business organisation view can be related to the business and IT view described later. This is shown in the diagram below with the IT Division responsible for IT Components.
Figure 2: Information Security Framework Relationships
