Addressing the weakest link: Implementing converged security

被引:14
作者
Aleem, Azeem [1 ]
Wakefield, Alison [2 ]
Button, Mark [2 ]
机构
[1] EMC Europe Ltd, RSA Secur Div EMC, Bracknell RG12 1RT, Berks, England
[2] Univ Portsmouth, Inst Criminal Justice Studies, Portsmouth PO1 2HY, Hants, England
关键词
physical security; information security; IT security; cyber security; convergence; enterprise risk management;
D O I
10.1057/sj.2013.14
中图分类号
DF [法律]; D9 [法律];
学科分类号
0301 ;
摘要
Reliance on technology presents one of the weakest links in contemporary organisational security, as certain threats can fall into the functional gaps between physical and information technology (IT) security departments. These can be described as 'converged threats' when an IT-based attack delivers an impact, such as a virus attack that halts the operation of critical infrastructure, or a physical attack on a system that compromises the security of data, such as an intruder or dishonest employee installing devices on computers to enable the stealing of electronic data. The aim of this article is to present and reflect on a converged approach to organisational security risk management as a means of addressing blended threats. We discuss this idea of converged security in the context of wider trends towards enterprise-wide approaches to risk management, and present a model demonstrating how converged security can be undertaken without a fundamental restructuring of these two key functions.
引用
收藏
页码:236 / 248
页数:13
相关论文
共 27 条
[11]  
Briggs R., 2006, The business of resilience: Corporate security for the 21st century
[12]  
Button M, 2008, CRIME PREV SECUR MAN, P1, DOI 10.1057/9780230583634
[13]  
Cabinet Office, 2012, UK CYB SEC STRAT
[14]  
Garcia M L., 2006, The handbook of security
[15]  
Hamilton Booz Allen, 2005, CONV ENT SEC ORG
[16]  
Hamilton G., 1996, Risk Management 2000
[17]  
Kovacich G., 2006, Security Metrics Management
[18]  
KPMG, 2011, E CRIM REP 2011 MAN
[19]  
Loveday B., 2006, INT J POLICE SCI MAN, V8, P282, DOI DOI 10.1350/IJPS.2006.8.4.282
[20]  
Overview of Enterprise Risk Management,, 2003, CASUALTY ACTUARIAL S