A Management Perspective on Risk of Security Threats to Information Systems

A Management Perspective on Risk of Security Threats to Information Systems
复制标题

信息系统安全威胁风险的管理视角

DOI:
10.1007/s10799-005-5880-5
复制
发表时间:
2005
影响因子:
2.4
通讯作者:
P. Enslow
P. Enslow
中科院分区:
管理学4区
文献类型:
--
作者:
Fariborz Farahmand;S. Navathe;G. Sharp;P. Enslow

文献摘要

被引文献

相似文献

电子商务和互联网使企业能够降低成本,扩大市场范围,并建立更密切的伙伴和客户关系。然而,使用互联网带来了新的风险和担忧。本文提供了一个管理的角度对CIO和IT经理面临的问题:它概述了电子商务的安全性,管理人员面临的重要问题,安全执法措施/技术,以及潜在的威胁和攻击的当前状态。它开发了一个计划的概率评估的影响,安全威胁的一些说明性的例子。该方法可用于评估对组织中的信息资产的攻击成功的概率,并评估这些攻击的预期损害。本文还概述了一些可能的补救措施、建议的控制措施和对策。最后,它提出了成本模型的发展,量化这些攻击的损害和面对这些攻击的努力。一个这样的安全风险评估成本模型的建设也概述。它有助于决策者选择适当的对策,以尽量减少安全事故造成的损害/损失。最后,对未来的工作提出了一些建议,以提高组织整体的安全管理水平。
Electronic commerce and the Internet have enabled businesses to reduce costs, attain greater market reach, and develop closer partner and customer relationships. However, using the Internet has led to new risks and concerns. This paper provides a management perspective on the issues confronting CIO’s and IT managers: it outlines the current state of the art for security in e-commerce, the important issues confronting managers, security enforcement measure/techniques, and potential threats and attacks. It develops a scheme for probabilistic evaluation of the impact of security threats with some illustrative examples. This methodology may be used to assess the probability of success of attacks on information assets in organizations, and to evaluate the expected damages of these attacks. The paper also outlines some possible remedies, suggested controls and countermeasures. Finally, it proposes the development of cost models which quantify damages of these attacks and the effort of confronting these attacks. The construction of one such cost model for security risk assessment is also outlined. It helps decision makers to select the appropriate choice of countermeasure(s) to minimize damages/losses due to security incidents. Finally, some recommendations for future work are provided to improve the management of security in organizations on the whole.