首页> 外文学位 >Application of Q-methodology in critical success factors of information security risk management.
【24h】

Application of Q-methodology in critical success factors of information security risk management.

机译:Q方法论在信息安全风险管理的关键成功因素中的应用。

获取原文
获取原文并翻译 | 示例

摘要

With more organizations undertaking information security initiatives, there is increasing awareness among Information Technology (IT) professionals regarding the risk management process. Successful implementation of a well-developed information security program depends on identifying the critical success factors (CSF) of risk management. An understanding of experiences and perspectives of IT professionals regarding the CSF is central to the delivery of a quality risk management process. Implicit with this is a need to understand the attributes and characteristics of these individuals, their subjectivity. Past studies have attempted to address this need by identifying a list of general CSF through interviews, case studies, and large surveys. In this paper, Q-methodology is offered as an alternative approach which provides insight into individual subjectivity through the use of factor analysis.;Within Q-methodology, individuals are asked to rank-order statements (Q-sort), which are then inter-correlated and subjected to factor analysis. In this way, groups of individuals holding similar viewpoints or opinions are identified. The factors are then interpreted to provide an understanding of underlying subjectivities. This paper explores the theoretical underpinnings of Q-methodology and its application as a research method in the field of information security.;In this study, we interviewed 50 IT professionals from various organizations, and systematically examined their subjectivity by applying the principles of Q-methodology. Our research revealed three distinct types of perspectives regarding the critical success factors in information security risk management initiatives. Our study also found senior management support to be the most critical success factor in such initiatives. However, the study revealed a difference of understanding between two groups of participants regarding the criticality of senior management support. Finally, our study found pre-selecting a risk assessment method is considered to be the least critical success factor in information security risk management.
机译:随着越来越多的组织采取信息安全计划,信息技术(IT)专业人员对风险管理流程的意识日益增强。成功实施完善的信息安全计划取决于确定风险管理的关键成功因素(CSF)。了解IT专业人员有关CSF的经验和观点对于交付质量风险管理流程至关重要。隐式地需要理解这些人的属性和特征,以及他们的主观性。过去的研究试图通过访谈,案例研究和大型调查来确定一般CSF列表,从而满足这一需求。本文将Q方法作为一种替代方法,通过使用因素分析提供对个人主观性的洞察力;在Q方法中,要求个人对陈述进行排序(Q-sort),然后将其相互-相关并进行因子分析。通过这种方式,可以确定持有相似观点或观点的个人群体。然后解释这些因素以提供对潜在主观性的理解。本文探讨了Q-方法论的理论基础及其在信息安全领域中作为研究方法的应用。在本研究中,我们采访了来自各个组织的50名IT专业人员,并通过应用Q-方法的原理系统地检查了他们的主观性。方法。我们的研究揭示了关于信息安全风险管理计划中关键成功因素的三种不同类型的观点。我们的研究还发现,高级管理层的支持是此类计划中最关键的成功因素。但是,研究显示两组参与者对高级管理支持的重要性的理解存在差异。最后,我们的研究发现,预先选择风险评估方法被认为是信息安全风险管理中最不重要的成功因素。

著录项

  • 作者

    Imroz, Sohel M.;

  • 作者单位

    University of Nebraska at Omaha.;

  • 授予单位 University of Nebraska at Omaha.;
  • 学科 Information Science.
  • 学位 M.S.
  • 年度 2009
  • 页码 126 p.
  • 总页数 126
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 信息与知识传播;
  • 关键词

  • 入库时间 2022-08-17 11:37:42

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号