Information Technology Consulting Firms’ Readiness for Managing Information Security Incidents

1Citations
Citations of this article
9Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Because of the increase in the number and scope of information security incidents, proper management has recently gained importance for public and private organizations. Further challenges in this area have resulted from new regulations, such as the General Data Protection Regulation (GDPR) and the Directive on Security of Network and Information Systems (NIS), as well as a tendency to outsource vital services to subcontractors. This study addresses the lack of empirical studies in the field and focuses on information security incident management at information technology (IT) consulting firms. Specifically, it examines challenges due to their exposed position and new regulations. The contribution of the paper is twofold. First, it provides valuable insight into the experiences and challenges of Swedish IT consulting firms. Second, it proposes criteria for classifying an information security incident that can equip decision-makers with a solid and assessable basis for incident management. The results emphasize further improvements in employee awareness, incident classification, and systemic governance, thereby integrating corporate policy making, information security incident management, and information system leadership.

Cite

CITATION STYLE

APA

Große, C., Nyman, M., & Sundberg, L. (2020). Information Technology Consulting Firms’ Readiness for Managing Information Security Incidents. In Communications in Computer and Information Science (Vol. 1221 CCIS, pp. 48–73). Springer. https://doi.org/10.1007/978-3-030-49443-8_3

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free