Improving Information Security Risk Analysis Practices for Small- and Medium-Sized Enterprises: A Research Agenda
TL;DR: A case for and a roadmap for developing an “ open development” strategy to address recognized deficiencies in the area of risk analysis to include developing a multi-level risk assessment methodology and set of decision heuristics designed to minimize the intellectu al effort required to conduct SME infrastructure level risk assessments.
read more
Abstract: Despite the availability of numerous methods and publications concerning the proper conduct of information security risk analyses, small and mediu m sized enterprises (SMEs) face serious organizational challenges managing the deployment and use of these tools and methods to assist them in selecting and implementing security safegua rds to prevent IS security compromises. This paper builds a case for and then outlines a possibl e approach and a multi-faceted research agenda for developing an “ open development” strategy to address recognized deficiencies in the area of risk analysis to include developing: a multi-level risk assessment methodology and set of decision heuristics designed to minimize the intellectu al effort required to conduct SME infrastructure level risk assessments, a set of decision heuristic s to assist in the quantification of organizational costs, financial as well as non-financial, a knowle dge base of probability estimates associated with specified classes of threats for use in the ap plication of the aforementioned methodology and automated tool(s) capable of supporting the executi on of the aforementioned methodology and heuristics.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Managing Risks in SMEs: A Literature Review and Research Agenda
Chiara Verbano,Karen Venturini +1 more
TL;DR: In this paper, the authors analyze available literature on the subject of risk management for small and medium-sized enterprises from 1999 to 2009, and highlight gaps and guidelines for future research.
Enabling Information Security Culture: Influences and Challenges for Australian SMEs
Sneza Dojkovski,Sharman Lichtenstein,Matthew Warren +2 more
- 01 Jan 2010
TL;DR: The findings highlight that SME owner attitudes and behaviour – in turn influenced by government involvement - strongly influence information security culture for Australian SMEs.
A review of research on risk analysis methods for IT systems
Sardar Muhammad Sulaman,Kim Weyns,Martin Höst +2 more
- 14 Apr 2013
TL;DR: A systematic mapping study on risk analysis for IT systems shows that many new risk analysis methods have been proposed in the last decade but even more that there is a need for more empirical evaluations of the different riskAnalysis methods.
33
Information Security Expenditures: a Techno-Economic Analysis
Theodosios Tsiakis
- 01 Jan 2010
TL;DR: The aims of this paper are to gain an understanding of Quantitative and Qualitative analysis and furthermore to both evaluate and improve the use of those methods.
References
The Delphi Method: Techniques and Applications
P. G. Moore
- 01 Mar 1977
TL;DR: This Report presents an elementary cross-impact model where the cross-impacts are formulated as relative probabilities.
4.5K
The mythical man-month: Essays on software engineering
TL;DR: The Rapid Selector, a bibliographic machine and a close cousin of the Memex of faddish fame, and the Comparator, a cryptanalytic device-provide the stuff to fill in the holes in the history of the computer.
1.8K
Coping with systems risk: security planning models for management decision making
TL;DR: Results of comparative qualitative studies in two information services Fortune 500 firms identify an approach that can effectively deal with systems risk, and this theory-based security program includes use of a security risk planning model, education/training in security awareness, and Countermeasure Matrix analysis.
•Book
Secrets and Lies: Digital Security in a Networked World
Bruce Schneier
- 01 Jan 2000
TL;DR: This book argues that modern systems have so many components and connections-some of them not even known by the systems' designers, implementers, or users-that insecurities always remain, and that the world was full of bad security systems designed by people who read Applied Cryptography.
•Book
Principles of Information Security
Michael E. Whitman,Herbert J. Mattord +1 more
- 12 Dec 2002
TL;DR: Principles of Information Security, Third Edition builds on internationally recognized standards and bodies of knowledge to provide the knowledge and skills that information systems students need for their future roles as business decision-makers.
1.2K