The significance of securing as a critical component of information security: An Australian narrative

The significance of securing as a critical component of information security: An Australian narrative
复制标题

DOI:
10.1016/j.cose.2019.101601
复制
发表时间:
2019-11-01
影响因子:
5.6
通讯作者:
Coles-Kemp, Lizzie
Coles-Kemp, Lizzie
中科院分区:
计算机科学3区
文献类型:
--
作者:
Burdon, Mark;Coles-Kemp, Lizzie

文献摘要

被引文献

相似文献

随着信息安全被要求在日益不稳定的空间中运行,信息安全从业者的角色变得越来越复杂。成功的信息安全实践取决于将保护需求置于组织目标范围内的策略和策略。随着组织受到数字技术的颠覆,这些策略和策略变得越来越重要。控制点在组织内的各个群体之间的分布是不可预测的。因此,就安全需求达成共识变得具有挑战性。信息安全控制是控制结构的重要组成部分,但它们越来越多地成为协商控制,使得保护过程与安全机制本身一样重要。我们采用更广泛的政治和社会安全理论,尤其是 Smith (2005),来分析来自澳大利亚信息安全从业者的九次半结构化访谈的数据。我们的研究结果描绘了安全和安全的相互关联的概念。安全性很简单。这是一种安全的状态。另一方面,确保安全是很复杂的。这是一个寻求共识、价值参与的过程,能够实现安全。通过这种分析,我们确定了参与者默认采用的安全流程和技术。有效安全实践的核心是参与者“正确获取安全信息”的能力。该消息用于在充满冲突的环境中建立一致的价值共识。我们认为,安全常常被低估,并且没有被视为信息安全学科的独特理论部分。然而,考虑到信息安全实践的复杂性和不确定性,我们认为安全需要被视为安全的关键组成部分。 (C) 2019 Elsevier Ltd. 保留所有权利。
As information security is called upon to operate in increasingly unstable spaces, the role of the information security practitioner becomes ever more complex. Successful information security practice depends on tactics and strategies that situate the need for protection within organisational goals. These tactics and strategies have become progressively important as organisations are disrupted by digital technology. The locus of control is unpredictably distributed across groups within an organisation. Finding consensus about the need for security thus becomes challenging. Information security controls are an important part of the control structure but increasingly they are negotiated controls, making the process of securing as important as the security mechanisms themselves. We employ broader political and social theories of security, most notably Smith (2005), to analyse data from nine semi-structured interviews of Australian information security practitioners. Our findings delineate the interlinking concepts of securing and security. Security is straightforward. It is a state of being secure. Securing, on the other hand, is complex. It is a consensus-seeking, value-engagement process that enables the attainment of security. Through this analysis, we identify processes and techniques of securing tacitly employed by the participants. Central to effective securing practice is a participant's ability to, 'get the security message right.' The message is used to create an agreed value consensus across conflict-ridden environments. We contend that securing is often undervalued and not recognised as a distinct theoretical part of the discipline of information security. However, given the complexity and uncertainty of information security practice, we argue that securing needs to be considered as a critical component of being secure. (C) 2019 Elsevier Ltd. All rights reserved.