Information security landscape and maturity level: Case study of Malaysian Public Service (MPS) organizations

被引:16
作者
Dzazali, Suhazimah [1 ]
Sulaiman, Ainin [1 ]
Zolait, Ali Hussein [1 ]
机构
[1] Univ Malaya, Fac Business & Accountancy, Kuala Lumpur, Malaysia
关键词
Information security; Public Service organizations; Security management;
D O I
10.1016/j.giq.2009.04.004
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
Information protection is of paramount importance in today's world. From information involving the highest level of government administration and national security, to information existing at the level of the private company in the form of trade secrets or personal data, all are under the constant threat of being compromised. In this study, the researchers attempt to evaluate the information security maturity level and provide clear thoughtful analysis of the information security landscapes of the Malaysian Public Service (MPS) organizations. This study uses convenience sampling and the required data collected from 970 targeted individuals through a self-administrated survey. In addition, a survey questionnaire is utilized to gauge the security landscape and to further understand the occurrence of incidents, the sources of attack, and the types of technical safeguard. Findings revealed that the highest security incidents experienced by the MPS were spamming (42%), followed by attacks of malicious codes (41%). Twenty-five percent of incidents originated from within the organizations, 15% originated from outside, and 11% were from a mixture of internal and external sources. Also, it shows that 49% of incidents were from sources unknown to the respondents. The top most deployed safeguards by the MPS were found to be firewalls (95%), followed by anti-virus software (92%), and access control to information system (89%). Findings on the maturity level show that 61% of respondents are at Level 3, followed by 21% at Level 2 where the information security processes are still considered an Information and Communication Technology (ICT) domain. At the higher end of the continuum lies 13% for Level 4 and 1% at Level 5. (C) 2009 Elsevier Inc. All rights reserved.
引用
收藏
页码:584 / 593
页数:10
相关论文
共 54 条
[1]  
ACEITUNO VC, 2004, ISM310 INFORM SECURI
[2]  
ANDERSEN WP, 2001, INFORM SECURITY TECH, V6, P60
[3]  
BASKERVILLE R, 1998, DESIGNING INFORM SYS
[4]  
Bhaskar K.N., 1993, Computer security: Threats and countermeasures
[5]  
*BRIT STAND INF SE, 2000, BS7799 BRIT STAND IN
[6]  
BRYNES C, 2005, GARTNER GROUP INFORM
[7]  
Caralli R., 2003, CHALLENGES SECURITY
[8]  
*COBIT, 2000, CONTR OBJ INF REL TE
[9]  
COBIT, 2002, CONTR OBJ INF REL TE
[10]   Information system security management in the new millennium [J].
Dhillon, G ;
Backhouse, J .
COMMUNICATIONS OF THE ACM, 2000, 43 (07) :125-128