A framework for security modeling using knowledge engineering

Organisational Information Systems - as well as related performance and control systems - were modelled on the same paradigm to enable convergence by ensuring adherence to classical information processes routines built into formal and informal information systems. However, this model is increasingly inadequate in the e-Information Systems era that is often characterised by an increasing pace of radical and unforeseen change in the Organisational environments, Information Systems and underlying Security. The new era of dynamic and discontinuous change requires continual reassessment of information and organisational routines to ensure that decision-making processes, as well as underlying assumptions, keep pace with the dynamically changing Information environments. One such conceptualisation is proposed in this article in the form of a framework for developing Organisational Information Security Model using Knowledge Management. The popular technology-centric interpretations of Information Security and Knowledge Management that have been prevalent in most of the information technology research and trade press are reviewed.