Corporate information security management
Управление информационной безопасностью предприятия
1999-09-01
SCID: 54.1/8vmper6z
Discuss with AI
business continuitycorporate information securityinformation security managementsecurity incident preparednesssecurity risk analysis
Figures from the paper
Abstract (AI)
To ensure business continuity the security of corporate information is extremely important. Previous studies have shown that corporate information is vulnerable to security attacks. Companies are losing money through security breaches. This paper describes an MSc project that aimed to investigate the issues surrounding corporate information security management. Postal questionnaires and telephone interviews were used. Findings indicate that companies are not proactively tackling information security management and thus are not prepared for security incidents when they occur. Reasons for this lack of action include: awareness of information security threats is restricted; management and awareness of information security is concentrated around the IT department; electronic information is viewed as an intangible business asset; potential security risks of Internet access have not been fully assessed; and surveyed companies have not yet encountered security problems, and therefore are unprepared to invest in security measures. The recommendations include that companies: carry out a formal risk analysis; move information security management from being an IT‐centric function; and alter perceptions towards electronic information so that information is viewed as a valuable corporate asset.
Key Findings
1
Companies are not proactively managing information security and are consequently unprepared to respond to security incidents.
2
Companies that have not previously experienced security problems are especially unlikely to invest in preventive security measures.
3
Information-security awareness and management are largely confined to IT departments rather than integrated across organizations.
4
Limited threat awareness, undervaluation of electronic information, and inadequate assessment of Internet risks hinder security investment.
5
The study recommends formal risk analysis, organization-wide security governance, and treating electronic information as a valuable corporate asset.
Research Object
corporate information security management in companies
Research Subject
companies’ preparedness, practices, and organizational barriers in managing information security and responding to security incidents
Publication Details
Publication Date
1999-09-01
Journal
Publisher
ISSN
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest