The Dynamics of Organizational Information Security

نویسندگان

  • Amitava Dutta
  • Rahul Roy
چکیده

In recent times, it has become evident that information security is not achieved through technology alone. Rather, it depends on a complex interplay among technology, organizational and managerial issues, and events in the external environment. Senior management attention, training, and sound operating procedures are just as important as firewalls and virtual private networks in arriving at a robust security posture. In this paper, we represent the interactions among these technical and organizational drivers using the system dynamics methodology, to develop a high level model of organizational information security. Since the basic system dynamics construct is the feedback loop, our model is able to expose the counteracting mechanics that work to reinforce and erode security, respectively. By doing so, it can inform the process of crafting an appropriate level of security—a problem facing most organizations. Since the model is based on simulation, it is also possible to test what-if scenarios of how the security posture of the organization would fare under different levels of external threats and management policies.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

The effect of developing the dynamics of library software system on information security management (Case study: Libraries of Islamic Azad universities of the country)

Background and Objective: Information security is of vital importance in most organizations. This is especially central in academic libraries due to the specific type of visitors, exchange and transfer of information to the users. Thus, the purpose   is to investigate the relationship of the development of library software and information security management in the libraries of Islamic Azad Uni...

متن کامل

از پیاده سازی معماری سرویس گرا تا چابکی سازمان با رویکرد مدلسازی پویایی سیستم

SOA is type of architecture that used service to simplify integration activities and use the components for reusable. Companies to survive in the dynamic environment needed to strengthen their organizations through information systems and service-oriented architecture is a way for the integration and effectiveness of the use of information systems and achieve organizational agility. In this pap...

متن کامل

Exploring the Type of Relationship between Information Security Management and Organizational Culture (Case Study in TAM Iran Khodro Co.)

A culture conducive to information security practice is extremely important for organizations since information has to be critical assets in modern enterprises. Thus for understanding and improving the organizational behavior with regard to information security, enterprises may look into organizational culture and examine how it affects the effectiveness of implementing ISM. This study aims ...

متن کامل

Exploring the Type of Relationship between Information Security Management and Organizational Culture (Case Study in TAM Iran Khodro Co.)

A culture conducive to information security practice is extremely important for organizations since information has to be critical assets in modern enterprises. Thus for understanding and improving the organizational behavior with regard to information security, enterprises may look into organizational culture and examine how it affects the effectiveness of implementing ISM. This study aims ...

متن کامل

Identifying Information Security Risk Components in Military Hospitals in Iran

Background and Aim: Information systems are always at risk of information theft, information change, and interruptions in service delivery. Therefore, the present study was conducted to develop a model for identifying information security risk in military hospitals in Iran. Methods: This study was a qualitative content analysis conducted in military hospitals in Iran in 2019. The sample consist...

متن کامل

Identifying the challenges and opportunities of organizational development in the oil industry through technology

The purpose of this study was to identifying the challenges and opportunities of organizational development in the oil industry through technology. This research was from a type qualitative research. The statistical population of the study included managers and employees in the oil industry. Semi-structured interviews were conducted using targeted snowball sampling method, 13 managers and emplo...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2017