Triangulating the Views of Human and Non-Human Stakeholders in Information System Security Risk Assessment

نویسندگان

  • Lizzie Coles-Kemp
  • Richard E. Overill
چکیده

The risk assessment methodologies that are portrayed in traditional information security management literature often do not scale into the multi-level stakeholder environment of corporate governance. This is because they focus on one type of stakeholder, the IT infrastructure. A risk assessment methodology that is to successfully operate in such an environment must have effective mechanisms of including and incorporating the risk perceptions of the different stakeholders. This does not mean that the traditional forms of information security risk assessment should be replaced; on the contrary they are extremely necessary. Rigorous IT infrastructure risk assessment is fundamental to good security management. However in environments where the operational processes for using the information are complex and dynamic, another aspect of risk, namely business or operational process security risk assessment needs to take place. Whilst this view of security risk assessment in itself is not a new concept and can be found as dominant aspects of security risk assessment methodologies such as Sherwood Applied Business Security Architecture (SABSA) and Facilitated Risk Analysis and Assessment Process (FRAAP), there has been little discussion as to how to include the operational process view without detracting from the technical IT asset view. This work considers how interaction between the stakeholders might take place and this short paper explores the different techniques to promote inclusiveness of the different stakeholder communities in the risk assessment process. The case studies that are used in this paper are the results of five years of field observations.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A risk model for cloud processes

Traditionally, risk assessment consists of evaluating the probability of "feared events", corresponding to known threats and attacks, as well as these events' severity, corresponding to their impact on one or more stakeholders. Assessing risks of cloud-based processes is particularly difficult due to lack of historical data on attacks, which has prevented frequency-based identification...

متن کامل

Clinical governance in primary health care based on family physicians in Mazandaran province: Stakeholders perspective

Background and Aim: Clinical governance is one of the important frameworks for continuous quality improvement and safety in health care systems. Identifying the axes of this approach according to local conditions is one of the important priorities of the health system. The aim of this study was to identify the views of stakeholders on the axes of clinical governance in primary health care based...

متن کامل

Stakeholder perspectives on relationship between factors affecting readiness for radio frequency identification implementation

Introduction: Radio Frequency Identification (RFID) is a type of automatic identification technology which uses radio waves for collecting and transferring data. Due to extensive use in tracking and identifying people and objects, this technology has been able to solve many of the hospital's problems and help to increase the quality of delivery of services. The aim of this study was to survey t...

متن کامل

ارائه الگویی برای ارزیابی ریسک آتش‌سوزی‌های عمدی

Background & Objectives : It is not possible to live without using fire. However, fire could destruct human properties in a short time. One of the most important types of fire is intentional fire. This type of fire has become a great problem for insurance companies, fire departments, industries, government and business in the recent years. This study aimed to provide a framework for risk assess...

متن کامل

The Views of Stakeholders About the Challenges of Rural Family Physician in Kurdistan Province: A Qualitative Study

Background and Objectives: The Family Physician (FP) plan was implemented in rural areas and cities with a population of less than 20000 in 2005. The purpose of this study was to explain the challenges and obstacles of¬ the Rural Family Physician Program in Kurdistan Province from the perspective of stakeholders.   Methods: This qualitative study was conducted using 30 semi-structured intervi...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2007