Coping with systems risk: Security planning models for management decision making

被引:552
作者
Straub, DW [1 ]
Welke, RJ [1 ]
机构
[1] Georgia State Univ, Coll Business Adm, Dept Comp Informat Syst, Atlanta, GA 30302 USA
关键词
information security planning; systems security risk; security awareness training; action research;
D O I
10.2307/249551
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The likelihood that the firm's information systems are insufficiently protected against certain kinds of damage or loss is known as "systems risk." Risk can be managed or reduced when managers are aware of the full range of controls available and implement the most effective controls. Unfortunately, they often lack this knowledge, and their subsequent actions to cope with systems risk are less effective than they might otherwise be. This is one viable explanation for why losses from computer abuse and computer disasters today are uncomfortably large and still so potentially devastating after many years of attempting to deal with the problem. Results of comparative qualitative studies in two information services Fortune 500 firms identify an approach that can effectively deal with the problem. This theory-based security program includes (I) use of a security risk planning model, (2) education/training in security awareness, and (3) Countermeasure Matrix analysis.
引用
收藏
页码:441 / 469
页数:29
相关论文
共 83 条
[1]  
*ABA, 1984, REP COMP CRIM
[2]  
AICPA, 1984, REP STUD EDP REL FRA
[3]  
[Anonymous], 1993, J MANAGE
[4]  
Badenhorst K. P., 1989, Computers & Security, V8, P433, DOI 10.1016/0167-4048(89)90025-4
[5]   SMIS Members: A Membership Analysis [J].
Ball, Leslie ;
Harris, Richard .
MIS QUARTERLY, 1982, 6 (01) :19-38
[6]   Modeling IT ethics: A study in situational ethics [J].
Banerjee, D ;
Cronan, TP ;
Jones, TW .
MIS QUARTERLY, 1998, 22 (01) :31-60
[7]  
Baskerville R., 1991, Computers & Security, V10, P749, DOI 10.1016/0167-4048(91)90094-T
[8]   INFORMATION-SYSTEMS SECURITY DESIGN METHODS - IMPLICATIONS FOR INFORMATION-SYSTEMS DEVELOPMENT [J].
BASKERVILLE, R .
COMPUTING SURVEYS, 1993, 25 (04) :375-414
[9]  
BASKERVILLE R, 1998, IN PRESS EUROPEAN J
[10]  
BASKERVILLE R, 1988, DESIGNING INFORMATIO