期刊论文详细信息
Australasian Journal of Information Systems
Information Security Risk Management: An Intelligence-Driven Approach
Jeb Webb1  Atif Ahmad1  Graeme Shanks1  Sean Maynard1 
[1] University of Melbourne
关键词: Information;    Security;    Risk Management;    Enterprise Situation Awareness;    Intelligence;   
DOI  :  10.3127/ajis.v18i3.1096
学科分类:计算机科学(综合)
来源: University of Canberra * Faculty of Information Sciences and Engineering
PDF
【 摘 要 】

Three deficiencies exist in the organisational practice of information security risk management: risk assessments are commonly perfunctory, security risks are estimated without investigation; risk is assessed on an occasional (as opposed to continuous) basis. These tendencies indicate that important data is being missed and that the situation awareness of decision-makers in many organisations is currently inadequate. This research-in-progress paper uses Endsley's situation awareness theory, and examines how the structure and functions of the US national security intelligence enterprise—a revelatory case of enterprise situation awareness development in security and risk management—correspond with Endsley’s theoretical model, and how facets of the US enterprise might be adapted to improve situation awareness in the information security risk management process of organisations.

【 授权许可】

Unknown   

【 预 览 】
附件列表
Files Size Format View
RO201912020431071ZK.pdf 269KB PDF download
  文献评价指标  
  下载次数:16次 浏览次数:42次