首页> 外文OA文献 >An Analysis of the Impact of Information Security Policies on Computer Security Breach Incidents in Law Firms
【2h】

An Analysis of the Impact of Information Security Policies on Computer Security Breach Incidents in Law Firms

机译:信息安全政策对律师事务所计算机安全违规事件的影响分析

摘要

Law firms maintain and store voluminous amounts of highly confidential and proprietary data, such as attorney-client privileged information, intellectual properties, financials, trade secrets, personal, and other sensitive information. There is an ethical obligation to protect law firm client data from unauthorized access. Security breaches jeopardize the reputation of the law firm and could have a substantial financial impact if these confidential data are compromised. Information security policies describe the security goals of a law firm and the acceptable actions and uses of law firm information resources.In this dissertation investigation, the author examined the problem of whether information security policies assist with preventing unauthorized parties from accessing law firm confidential and sensitive information. In 2005, Doherty and Fulford performed an exploratory analysis of security policies and security breach incidents that highlighted the need for research with different target populations. This investigation advanced Doherty and Fulfordu27s research by targeting information security policies and security breach incidents in law firms. The purpose of this dissertation investigation was to determine whether there is a correlation between the timing of security policy development (proactive versus reactive policy development) and the frequency and severity of security breach incidents in law firms of varying sizes.Outcomes of this investigation correlated with Doherty and Fulfordu27s general findings of no evidence of statistically significant relationships between the existence of a written information security policy and the frequency and severity of security breach incidents within law firms. There was also a weak relationship between infrequency of information security policy updates and increase of theft resources. Results demonstrated that, generally, written information security policies in law firms were not created in response to a security breach incident. These findings suggest that information security policies generally are proactively developed by law firms.Important contributions to the body of knowledge from this analysis included the effectiveness of information security policies in reducing the number of computer security breach incidents of law firms, an under represented population, in the information assurance field. Also, the analysis showed the necessity for law firms to become more immersed in state security breach notification law requirements.
机译:律师事务所维护并存储了大量的高度机密和专有数据,例如律师-客户的特权信息,知识产权,财务,商业秘密,个人信息和其他敏感信息。在道德上有义务保护律师事务所的客户数据免遭未经授权的访问。安全漏洞破坏了律师事务所的声誉,如果这些机密数据遭到破坏,可能会造成重大的财务影响。信息安全策略描述了律师事务所的安全目标以及律师事务所信息资源的可接受行为和使用。在本文的研究中,作者研究了信息安全策略是否有助于防止未授权方访问律师事务所的机密和敏感问题。信息。 2005年,Doherty和Fulford对安全策略和安全漏洞事件进行了探索性分析,突显了需要针对不同目标人群进行研究。该调查通过针对律师事务所的信息安全策略和安全漏洞事件,推进了Doherty和Fulford的研究。本研究旨在确定安全策略制定的时机(主动策略与被动策略的制定)之间的关系,以及不同规模律师事务所中安全漏洞事件的发生频率和严重性。 Doherty和Fulford的一般发现没有证据表明书面信息安全政策的存在与律师事务所内部安全漏洞事件的发生频率和严重程度之间存在统计上的显着关系。信息安全政策更新频率不高和盗窃资源增加之间的关系也很弱。结果表明,通常,律师事务所的书面信息安全策略并不是针对安全漏洞事件而创建的。这些发现表明,信息安全政策通常是由律师事务所主动制定的。此分析对知识体系的重要贡献包括信息安全政策在减少律师事务所,代表人数不足,在信息保证领域。此外,分析表明,律师事务所有必要更加沉浸于国家安全违规通知法律的要求中。

著录项

  • 作者

    Heikkila Faith M.;

  • 作者单位
  • 年度 2009
  • 总页数
  • 原文格式 PDF
  • 正文语种
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号