首页> 外文会议>International Conference on Security Management >Triangulating the Views of Human and non-Human Stakeholders in Information System Security Risk Assessment
【24h】

Triangulating the Views of Human and non-Human Stakeholders in Information System Security Risk Assessment

机译:在信息系统安全风险评估中将人类和非人类利益相关者的观点进行三角化

获取原文

摘要

The risk assessment methodologies that are portrayed in traditional information security management literature often do not scale into the multi-level stakeholder environment of corporate governance. This is because they focus on one type of stakeholder, the IT infrastructure. A risk assessment methodology that is to successfully operate in such an environment must have effective mechanisms of including and incorporating the risk perceptions of all the different stakeholders. This does not mean that the traditional forms of information security risk assessment should be replaced; on the contrary rigorous IT infrastructure risk assessment is fundamental to good security management. This work considers how interaction between the stakeholders might take place and this short paper explores the different techniques to promote inclusiveness of the different stakeholder communities in the risk assessment process and uses case studies and field observations gathered in 35 organisations over seven years to illustrate the theory.
机译:传统信息安全管理文献中描绘的风险评估方法通常不会扩展到公司治理的多级利益相关者环境。这是因为他们专注于一种类型的利益相关者,IT基础架构。在这种环境中成功运作的风险评估方法必须具有有效的机制,包括并纳入所有不同利益攸关方的风险看法。这并不意味着应更换传统的信息形式的信息安全风险评估;违反严格的IT基础设施风险评估是良好安全管理的基础。这项工作考虑了利益攸关方之间可能发生的互动,这篇短文探讨了促进不同利益相关方社区的不同技巧,在风险评估过程中,使用案例研究和在35多年组织中聚集的实地观察,以说明该理论。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号