Back to Search
Start Over
An Investigation Of Organizational Information Security Risk Analysis
- Source :
- Journal of Service Science (JSS). 3
- Publication Year :
- 2010
- Publisher :
- Clute Institute, 2010.
-
Abstract
- Despite a growing number and variety of information security threats, many organizations continue to neglect implementing information security policies and procedures. The likelihood that an organization’s information systems can fall victim to these threats is known as information systems risk (Straub & Welke, 1998). To combat these threats, an organization must undergo a rigorous process of self-analysis. To better understand the current state of this information security risk analysis (ISRA) process, this study deployed a questionnaire using both open-ended and closed ended questions administered to a group of information security professionals (N=32). The qualitative and quantitative results of this study show that organizations are beginning to conduct regularly scheduled ISRA processes. However, the results also show that organizations still have room for improvement to create idyllic ISRA processes.
- Subjects :
- Risk analysis
Information security management
Certified Information Security Manager
Risk analysis (engineering)
business.industry
Information security standards
Standard of Good Practice
Information system
Information security
Public relations
business
Security information and event management
Subjects
Details
- ISSN :
- 19414730 and 19414722
- Volume :
- 3
- Database :
- OpenAIRE
- Journal :
- Journal of Service Science (JSS)
- Accession number :
- edsair.doi...........dd7810e0c9972edaa4b7cd92588dd3dd
- Full Text :
- https://doi.org/10.19030/jss.v3i2.368