Factors influencing the implementation of information systems security strategies in organisations


Autoria(s): Park, Sangseo; Ahmad, Atif; Ruighaver, Anthonie
Contribuinte(s)

[Unknown]

Data(s)

01/01/2010

Resumo

Many organizations still rely on deterrence to control insider threats and on purely preventive strategies to control outsider threats. Such a simple approach to organizational information security is no longer viable given the increasing operational sophistication of current security threat agents and the complexity of information technology infrastructure. Effective implementation of security requires organizations to select a combination of strategies that work in tandem and best suits their security situation. This paper addresses the identification and classification of factors that influence implementation of security strategies in organizations. In this paper, we develop a preliminary architecture that aims to assist organizations in deciding how strategies can be designed to complement each other to improve the cost-effectiveness of security.<br />

Identificador

http://hdl.handle.net/10536/DRO/DU:30031569

Idioma(s)

eng

Publicador

IEEE

Relação

http://dro.deakin.edu.au/eserv/DU:30031569/ruighaver-factorsinfluencing-2010.pdf

http://dro.deakin.edu.au/eserv/DU:30031569/ruighaver-factorsinfluencing-evidence-2010.pdf

http://dx.doi.org/10.1109/ICISA.2010.5480261

Direitos

2010, IEEE

Palavras-Chave #information systems security #information systems security strategy #security requirements
Tipo

Conference Paper