Webbläsaren som du använder stöds inte av denna webbplats. Alla versioner av Internet Explorer stöds inte längre, av oss eller Microsoft (läs mer här: * https://www.microsoft.com/en-us/microsoft-365/windows/end-of-ie-support).

Var god och använd en modern webbläsare för att ta del av denna webbplats, som t.ex. nyaste versioner av Edge, Chrome, Firefox eller Safari osv.

Understanding Security Practices Deficiencies: A Contextual Analysis

Författare

  • Moufida Sadok
  • Peter Bednar

Redaktör

  • Steven Furnell
  • Nathan Clarke

Summary, in English

This paper seeks to provide an overview of how companies assess and manage security risks in practice. For this purpose we referred to data of security surveys to examine the scope of risk analysis and to identify involved entities in this process. Our analysis shows a continuous focus on data system security rather than on real world organizational context as well as a prevalent involvement of top management and security staff in risk analysis process and in

security policy definition and implementation. We therefore suggest that three issues need to be further investigated in the field of information security risk management in order to bridge the gap between design and implementation of secure and usable systems. First, there is a need to broaden the horizon to consider information system as human activity system which is different from a data processing system. Second, the involvement of relevant stakeholders in context for risk analysis leads to better appreciation of security risks. Third, it is necessary to develop ad-hoc tools and techniques to facilitate discussions and dialogue between stakeholders in risk analysis context.

Publiceringsår

2015

Språk

Engelska

Sidor

151-160

Publikation/Tidskrift/Serie

Human Aspects of Information Security and Assurance Conference Proceedings

Dokumenttyp

Konferensbidrag

Förlag

Centre for Security, Communications and Network Research, Plymouth University, UK

Ämne

  • Information Systems, Social aspects
  • Information Systems
  • Economics and Business
  • Computer and Information Science
  • Sociology

Nyckelord

  • Security surveys
  • Contextual analysis
  • Security practices
  • Risk analysis
  • Information security

Conference name

Ninth International Symposium on Human Aspects of Information Security & Assurance, HAISA 2015

Conference date

2015-07-01 - 2015-07-03

Conference place

Mytilene, Greece

Status

Published

ISBN/ISSN/Övrigt

  • ISBN: 978-1-84102-388-5