首页> 外文期刊>Journal of the Association for Information Science and Technology >How integration of cyber security management and incident response enables organizational learning
【24h】

How integration of cyber security management and incident response enables organizational learning

机译:网络安全管理和事件响应的集成如何实现组织学习

获取原文
获取原文并翻译 | 示例
           

摘要

Digital assets of organizations are under constant threat from a wide assortment of nefarious actors. When threats materialize, the consequences can be significant. Most large organizations invest in a dedicated information security management (ISM) function to ensure that digital assets are protected. The ISM function conducts risk assessments, develops strategy, provides policies and training to define roles and guide behavior, and implements technological controls such as firewalls, antivirus, and encryption to restrict unauthorized access. Despite these protective measures, incidents (security breaches) will occur. Alongside the security management function, many organizations also retain an incident response (IR) function to mitigate damage from an attack and promptly restore digital services. However, few organizations integrate and learn from experiences of these functions in an optimal manner that enables them to not only respond to security incidents, but also proactively maneuver the threat environment. In this article we draw on organizational learning theory to develop a conceptual framework that explains how the ISM and IR functions can be better integrated. The strong integration of ISM and IR functions, in turn, creates learning opportunities that lead to organizational security benefits including: increased awareness of security risks, compilation of threat intelligence, removal of flaws in security defenses, evaluation of security defensive logic, and enhanced security response.
机译:组织的数字资产受到各种各样的邪恶行为者的不断威胁。当威胁实现时,后果可能是显着的。大多数大型组织投资于专用信息安全管理(ISM)功能,以确保保护数字资产受到保护。 ISM函数进行风险评估,开发策略,提供策略和培训,以定义角色和指导行为,并实现防火墙,防病毒和加密等技术控制,以限制未经授权的访问。尽管有这些保护措施,事件(安全漏洞)将发生。除了安全管理功能外,许多组织还保留了事件响应(IR)函数,以减轻攻击损坏并及时恢复数字服务。然而,很少有组织以最佳的方式集成和学习这些功能的经验,使他们不仅可以响应安全事件,而且还积极地操纵威胁环境。在本文中,我们借鉴了组织学习理论来开发一个概念框架,解释了ISM和IR功能如何更好地集成。 ISM和IR职能的强大融合,反过来,依次创造了导致组织安全福利的学习机会,包括:提高安全风险的认识,威胁情报的汇编,安全防御缺陷,安全防御逻辑评估,以及增强的安全性回复。

著录项

  • 来源
  • 作者单位

    School of Computing and Information Systems University of Melbourne Parkville Victoria Australia;

    School of Management QUT Business School Queensland University of Technology Brisbane Queensland Australia;

    School of Computing and Information Systems University of Melbourne Parkville Victoria Australia;

    School of Computing and Information Systems University of Melbourne Parkville Victoria Australia;

    Robinson College of Business Georgia State University Atlanta Georgia Curtin Business School Curtin University Perth Australia;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号