首页> 外文会议>System Sciences (HICSS-43), 2010 >Managing Emerging Information Security Risks during Transitions to Integrated Operations
【24h】

Managing Emerging Information Security Risks during Transitions to Integrated Operations

机译:在过渡到集成运营期间管理新兴的信息安全风险

获取原文

摘要

The Norwegian Oil and Gas Industry is adopting new information communication technology to connect its offshore platforms, onshore control centers and the suppliers. The management of the oil companies is generally aware of the increasing risks associated with the transition, but so far, investment in incident response (IR) capability has not been highly prioritized because of uncertainty related to risks and the present reactive mental model for security risk management. In this paper, we extend previous system dynamics models on operation transition and change of vulnerability, investigating the role of IR capability in controlling the severity of incidents. The model simulation shows that a reactive approach to security risk management might trap the organization in low IR capability and lead to severe incidents. With a long-term view, proactive investment in IR capability is of financial benefit.
机译:挪威石油和天然气工业正在采用新的信息通信技术来连接其海上平台,陆上控制中心和供应商。石油公司的管理层通常意识到与过渡相关的风险不断增加,但是到目前为止,由于与风险相关的不确定性和当前的安全风险反应模型,对事件响应(IR)能力的投资尚未得到高度优先考虑管理。在本文中,我们扩展了先前关于操作转换和漏洞更改的系统动力学模型,研究了IR功能在控制事件严重性中的作用。模型仿真表明,安全风险管理的反应性方法可能会使组织陷入IR能力低下并导致严重事件的可能性。从长远来看,对IR能力的积极投资具有财务优势。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号