The duality of Information Security Management: fighting against predictable and unpredictable threats

  • Spagnoletti P
  • Resca A
N/ACitations
Citations of this article
40Readers
Mendeley users who have this article in their library.

Abstract

Information systems security is a challenging research area in the context of IS. In fact, it has strong practical implications for the management of Information Systems and, at the same time, it gives very interesting insights into understanding the process of social phenomena when communication information technologies are deployed in organizations. Current standards and best practices for the design and management of information systems security, recommend structured and mechanistic approaches, such as risk management methods and techniques, in order to address security issues. However, risk analysis and risk evaluation processes have their limitations, when security incidents occur, they emerge in a context, and their rarity and even their uniqueness give rise to unpredictable threats. The analysis of these phenomena which are characterized by breakdowns, surprises and side-effects, requires a theoretical approach which is able to examine and interpret subjectively the detail of each incident. The aim of this paper is to highlight the duality of information systems security, providing an alternative view on the management of those aspects already defined in the literature as intractable problems.

Cite

CITATION STYLE

APA

Spagnoletti, P., & Resca, A. (2008). The duality of Information Security Management: fighting against predictable and unpredictable threats. Journal of Information System Security, 4(3), 46–62. Retrieved from http://eprints.luiss.it/955/

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free