A case analysis of information systems and security incident responses

被引:55
作者
Ahmad, Atif [1 ]
Maynard, Sean B. [1 ]
Shanks, Graeme [1 ]
机构
[1] Univ Melbourne, Dept Comp & Informat Syst, Melbourne, Vic 3010, Australia
关键词
Information Security Management; Security learning; Incident Response Teams; Organizational learning; ORGANIZATIONS; KNOWLEDGE;
D O I
10.1016/j.ijinfomgt.2015.08.001
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
Our case analysis presents and identifies significant and systemic shortcomings of the incident response practices of an Australian financial organization. Organizational Incident Response Teams accumulate considerable experience in addressing information security failures and attacks. Their first-hand experiences provide organizations with a unique opportunity to draw security lessons and insights towards improving enterprise-wide security management processes. However, previous research shows a distinct lack of communication and collaboration between the functions of incident response and security management, suggesting organizations are not learning from their incident experiences. We subsequently propose a number of lessons learned and a novel security-learning model. Crown Copyright (C) 2015 Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:717 / 723
页数:7
相关论文
共 22 条
[1]  
Ahmad A., 2010, J INFORM SYSTEMS SEC, V6
[2]   Information security strategies: towards an organizational multi-strategy perspective [J].
Ahmad, Atif ;
Maynard, Sean B. ;
Park, Sangseo .
JOURNAL OF INTELLIGENT MANUFACTURING, 2014, 25 (02) :357-370
[3]  
Chan C., 2003, LEARNING HLTH SOCIAL, V2, P223
[4]  
Cichonski Paul, 2012, NIST Special Publication, V800, P1
[5]  
Cooke D.L., 2003, 21 SYST DYN C
[6]   An organizational learning framework: From intuition to institution [J].
Crossan, MM ;
Lane, HW ;
White, RE .
ACADEMY OF MANAGEMENT REVIEW, 1999, 24 (03) :522-537
[7]   Securing knowledge in organizations: lessons from the defense and intelligence sectors [J].
Desouza, KC ;
Vanapalli, GK .
INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2005, 25 (01) :85-98
[8]   A taxonomy of networks and computer attacks [J].
Hansman, S ;
Hunt, R .
COMPUTERS & SECURITY, 2005, 24 (01) :31-43
[9]  
Hove C, 2013, INFORM SECURITY INCI
[10]  
Killcrece G., 2003, Organizational Models for Computer Security Incident Response Teams (CSIRTs)