IT Risk Management: Towards a System for Enhancing Objectivity in Asset Valuation That Engenders a Security Culture

被引:1
|
作者
Metin, Bilgin [1 ]
Duran, Sefa [2 ]
Telli, Eda
Mutluturk, Meltem [1 ]
Wynn, Martin [2 ]
机构
[1] Bogazici Univ, Dept Management Informat Syst, Hisar Campus, TR-34342 Istanbul, Turkiye
[2] Univ Gloucestershire, Sch Business Comp & Social Sci, Cheltenham GL50 2RH, England
关键词
risk assessment; asset value; information security; risk management; objective risk assessment; segregation of duties; security culture framework; COBIT; 2019; international standards; cybersecurity; supply chain security;
D O I
10.3390/info15010055
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In today's technology-centric business environment, where organizations encounter numerous cyber threats, effective IT risk management is crucial. An objective risk assessment-based on information relating to business requirements, human elements, and the security culture within an organisation-can provide a sound basis for informed decision making, effective risk prioritisation, and the implementation of suitable security measures. This paper focuses on asset valuation, supply chain risk, and enhanced objectivity-via a "segregation of duties" approach-to extend and apply the capabilities of an established security culture framework. The resultant system design aims at mitigating subjectivity in IT risk assessments, thereby diminishing personal biases and presumptions to provide a more transparent and accurate understanding of the real risks involved. Survey responses from 16 practitioners working in the private and public sectors confirmed the validity of the approach but suggest it may be more workable in larger organisations where resources allow dedicated risk professionals to operate. This research contributes to the literature on IT and cyber risk management and provides new perspectives on the need to improve objectivity in asset valuation and risk assessment.
引用
收藏
页数:27
相关论文
共 50 条
  • [31] Asset criticality and risk prediction for an effective cybersecurity risk management of cyber-physical system
    Halima Ibrahim Kure
    Shareeful Islam
    Mustansar Ghazanfar
    Asad Raza
    Maruf Pasha
    Neural Computing and Applications, 2022, 34 : 493 - 514
  • [32] Asset criticality and risk prediction for an effective cybersecurity risk management of cyber-physical system
    Kure, Halima Ibrahim
    Islam, Shareeful
    Ghazanfar, Mustansar
    Raza, Asad
    Pasha, Maruf
    NEURAL COMPUTING & APPLICATIONS, 2022, 34 (01): : 493 - 514
  • [33] IABSE 2019 Guimaraes Symposium: Towards a Resilient Built Environment-Risk and Asset Management
    Sousa, Helder
    STRUCTURAL ENGINEERING INTERNATIONAL, 2019, 29 (03) : 481 - 483
  • [34] Research on Key Risk Index System of Asset Management in Power Grid Enterprise
    Cheng, Jia-xu
    Chen, Hao
    Chang, Yan
    3RD INTERNATIONAL CONFERENCE ON GREEN MATERIALS AND ENVIRONMENTAL ENGINEERING (GMEE), 2017, : 277 - 281
  • [35] Towards Optimal Risk-Aware Security Compliance of a Large IT System
    Coffman, Daniel
    Agrawal, Bhavna
    Schaffa, Frank
    SERVICE-ORIENTED COMPUTING, ICSOC 2013, 2013, 8274 : 639 - 651
  • [36] Enhancing IoT Security: An Innovative Key Management System for Lightweight Block Ciphers
    Rana, Muhammad
    Mamun, Quazi
    Islam, Rafiqul
    SENSORS, 2023, 23 (18)
  • [37] Towards an Automated and Dynamic Risk Management Response System
    Gonzalez-Granadillo, Gustavo
    Alvarez, Ender
    Motzek, Alexander
    Merialdo, Matteo
    Garcia-Alfaro, Joaquin
    Debar, Herve
    SECURE IT SYSTEMS, NORDSEC 2016, 2016, 10014 : 37 - 53
  • [38] Towards the ENTRI Framework: Security Risk Management Enhanced by the Use of Enterprise Architectures
    Mayer, Nicolas
    Grandry, Eric
    Feltus, Christophe
    Goettelmann, Elio
    ADVANCED INFORMATION SYSTEMS ENGINEERING WORKSHOPS, CAISE 2015, 2015, 215 : 459 - 469
  • [39] Towards Risk-Driven Security Requirements Management in Agile Software Development
    Ionita, Dan
    van der Velden, Coco
    Ikkink, Henk-Jan Klein
    Neven, Eelko
    Daneva, Maya
    Kuipers, Michael
    INFORMATION SYSTEMS ENGINEERING IN RESPONSIBLE INFORMATION SYSTEMS, CAISE FORUM 2019, 2019, 350 : 133 - 144
  • [40] Design of risk monitoring and prediction system for resource security management
    Zhao, Chunli
    Chen, Jianguo
    Sun, Zhanhui
    Du, Peng
    Yuan, Hongyong
    PROCEEDINGS OF THE 4TH ACM SIGSPATIAL INTERNATIONAL WORKSHOP ON SAFETY AND RESILIENCE (EM-GIS 2018), 2018,