Information security strategies: towards an organizational multi-strategy perspective

被引:58
作者
Ahmad, Atif [1 ]
Maynard, Sean B. [1 ]
Park, Sangseo [1 ]
机构
[1] Univ Melbourne, Melbourne Sch Engn, Dept Comp & Informat Syst, Parkville, Vic 3010, Australia
关键词
Information security strategy; Deterrence; Prevention; Compartmentalization; Deception; Defense in depth; SYSTEMS; DETERRENCE; DECEPTION; AWARENESS; FRAMEWORK; ABUSE; RISK;
D O I
10.1007/s10845-012-0683-0
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
There considerable advice in both research and practice oriented literature on the topic of information security. Most of the discussion in literature focuses on how to prevent security attacks using technical countermeasures even though there are a number of other viable strategies such as deterrence, deception, detection and response. This paper reports on a qualitative study, conducted in Korea, to determine how organizations implement security strategies to protect their information systems. The findings reveal a deeply entrenched preventive mindset, driven by the desire to ensure availability of technology and services, and a comparative ignorance of exposure to business security risks. Whilst there was some evidence of usage of other strategies, they were also deployed in a preventive capacity. The paper presents a research agenda that calls for research on enterprise-wide multiple strategy deployment with a focus on how to combine, balance and optimize strategies.
引用
收藏
页码:357 / 370
页数:14
相关论文
共 120 条
[1]   OFFENSIVE VERSUS DEFENSIVE - MILITARY STRATEGY AND ALTERNATIVE DEFENSE [J].
AGRELL, W .
JOURNAL OF PEACE RESEARCH, 1987, 24 (01) :75-85
[2]  
Alberts D.S., 1996, Defensive Information Warfare
[3]   Enterprise information security strategies [J].
Anderson, Evan E. ;
Choobineh, Joobin .
COMPUTERS & SECURITY, 2008, 27 (1-2) :22-29
[4]  
Anderson P., 2001, DECEPTION HLTH PART
[5]  
ANDERSON RH, 1996, EXPLORATION CYBERSPA
[6]  
[Anonymous], NATO REV
[7]  
[Anonymous], WORKSH CYB SEC CONT
[8]  
[Anonymous], TRENDS ISSUES CRIME
[9]  
[Anonymous], DARPA INF SURV C EXP
[10]  
[Anonymous], THESIS U ILLINOIS SP