A situation awareness model for information security risk management

被引:96
作者
Webb, Jeb [1 ]
Ahmad, Atif [1 ]
Maynard, Sean B. [1 ]
Shanks, Graeme [1 ]
机构
[1] Univ Melbourne, Melbourne Sch Engn, Dept Comp & Informat Syst, Melbourne, Vic 3172, Australia
关键词
Information security management; Information security risk management; Information security intelligence; Information security compliance; Information security investigation; Evidence-based information security; Situation awareness; Situation awareness theory; TRACKING; DESIGN;
D O I
10.1016/j.cose.2014.04.005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information security risk management (ISRM) is the primary means by which organizations preserve the confidentiality, integrity and availability of information resources. A review of ISRM literature identified deficiencies in the practice of information security risk assessment that inevitably lead to poor decision-making and inadequate or inappropriate security strategies. In this conceptual paper, we propose a situation aware ISRM (SA-ISRM) process model to complement the information security risk management process. Our argument is that the model addresses the aforementioned deficiencies through an enterprise-wide collection, analysis and reporting of risk-related information. The SA-ISRM model is adapted from Endsley's situation awareness model and has been refined using our findings from a case study of the US national security intelligence enterprise. (C) 2014 Elsevier Ltd. All rights reserved.
引用
收藏
页码:1 / 15
页数:15
相关论文
共 71 条
[1]   Survey and Analysis of Multimodal Sensor Planning and Integration for Wide Area Surveillance [J].
Abidi, Besma R. ;
Aragam, Nash R. ;
Yao, Yi ;
Abidi, Mongi A. .
ACM COMPUTING SURVEYS, 2008, 41 (01)
[2]   Incident response teams - Challenges in supporting the organisational security function [J].
Ahmad, Atif ;
Hadgkiss, Justin ;
Ruighaver, A. B. .
COMPUTERS & SECURITY, 2012, 31 (05) :643-652
[3]  
[Anonymous], 2007, JOINT PUBL OFF JOINT
[4]  
[Anonymous], US NAT INT OV
[5]  
[Anonymous], 2011, 270052011 ASNZS ISOI
[6]  
Baskerville R., 1991, European Journal of Information Systems, V1, P121, DOI 10.1057/ejis.1991.20
[7]  
Bedny G., 1999, International Journal of Cognitive Ergonomics, V3, P63, DOI [10.1207/s15327566ijce0301_5, DOI 10.1207/S15327566IJCE0301_5]
[8]  
Bolstad C., 2001, P HUMAN FACTORS ERGO, V45, P272, DOI [10.1177/154193120104500401, DOI 10.1177/154193120104500401]
[9]   CODING CHOICES FOR TEXTUAL ANALYSIS - A COMPARISON OF CONTENT-ANALYSIS AND MAP ANALYSIS [J].
CARLEY, K .
SOCIOLOGICAL METHODOLOGY 1993, VOL 23, 1993, 23 :75-126
[10]   Human and organisational factors in maritime accidents: Analysis of collisions at sea using the HFACS [J].
Chauvin, Christine ;
Lardjane, Salim ;
Morel, Gael ;
Clostermann, Jean-Pierre ;
Langard, Benoit .
ACCIDENT ANALYSIS AND PREVENTION, 2013, 59 :26-37