Corporate information security management

Управление информационной безопасностью предприятия
Ruth C. Mitchell, Rita Marcella, Graeme Baxter
1999-09-01

business continuitycorporate information securityinformation security managementsecurity incident preparednesssecurity risk analysis
To ensure business continuity the security of corporate information is extremely important. Previous studies have shown that corporate information is vulnerable to security attacks. Companies are losing money through security breaches. This paper describes an MSc project that aimed to investigate the issues surrounding corporate information security management. Postal questionnaires and telephone interviews were used. Findings indicate that companies are not proactively tackling information security management and thus are not prepared for security incidents when they occur. Reasons for this lack of action include: awareness of information security threats is restricted; management and awareness of information security is concentrated around the IT department; electronic information is viewed as an intangible business asset; potential security risks of Internet access have not been fully assessed; and surveyed companies have not yet encountered security problems, and therefore are unprepared to invest in security measures. The recommendations include that companies: carry out a formal risk analysis; move information security management from being an IT‐centric function; and alter perceptions towards electronic information so that information is viewed as a valuable corporate asset.
1
Companies are not proactively managing information security and are consequently unprepared to respond to security incidents.
2
Companies that have not previously experienced security problems are especially unlikely to invest in preventive security measures.
3
Information-security awareness and management are largely confined to IT departments rather than integrated across organizations.
4
Limited threat awareness, undervaluation of electronic information, and inadequate assessment of Internet risks hinder security investment.
5
The study recommends formal risk analysis, organization-wide security governance, and treating electronic information as a valuable corporate asset.

corporate information security management in companies

companies’ preparedness, practices, and organizational barriers in managing information security and responding to security incidents

Publication Details
Publication Date
1999-09-01
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Ruth C. Mitchell
Rita Marcella
Graeme Baxter
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%