On business-driven it security management and mismatches between security requirements in firms, industry standards and research Work

7Citations
Citations of this article
12Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Industry managers have long recognized the vital importance of information security for their businesses, but at the same time they perceived security as a technology-driven rather then a business-driven field. Today, this notion is changing and security management is shifting from technology- to business-oriented approaches. Whereas there is evidence of this shift in the literature, this paper argues that security standards and academic work have not yet taken it fully into account. We examine whether this disconnect has lead to a misalignment of IT security requirements in businesses versus industry standards and academic research. We conducted 13 interviews with practitioners from 9 different firms to investigate this question. The results present evidence for a significant gap between security requirements in industry standards and actually reported security vulnerabilities. We further find mismatches between the prioritization of security factors in businesses, standards and real-world threats. We conclude that security in companies serves the business need of protecting information availability to keep the business running at all times. © 2009 Springer Berlin Heidelberg.

Cite

CITATION STYLE

APA

Frühwirth, C. (2009). On business-driven it security management and mismatches between security requirements in firms, industry standards and research Work. In Lecture Notes in Business Information Processing (Vol. 32 LNBIP, pp. 375–385). Springer Verlag. https://doi.org/10.1007/978-3-642-02152-7_28

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free