IT Risk Management: Towards a System for Enhancing Objectivity in Asset Valuation That Engenders a Security Culture

被引:1
|
作者
Metin, Bilgin [1 ]
Duran, Sefa [2 ]
Telli, Eda
Mutluturk, Meltem [1 ]
Wynn, Martin [2 ]
机构
[1] Bogazici Univ, Dept Management Informat Syst, Hisar Campus, TR-34342 Istanbul, Turkiye
[2] Univ Gloucestershire, Sch Business Comp & Social Sci, Cheltenham GL50 2RH, England
关键词
risk assessment; asset value; information security; risk management; objective risk assessment; segregation of duties; security culture framework; COBIT; 2019; international standards; cybersecurity; supply chain security;
D O I
10.3390/info15010055
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In today's technology-centric business environment, where organizations encounter numerous cyber threats, effective IT risk management is crucial. An objective risk assessment-based on information relating to business requirements, human elements, and the security culture within an organisation-can provide a sound basis for informed decision making, effective risk prioritisation, and the implementation of suitable security measures. This paper focuses on asset valuation, supply chain risk, and enhanced objectivity-via a "segregation of duties" approach-to extend and apply the capabilities of an established security culture framework. The resultant system design aims at mitigating subjectivity in IT risk assessments, thereby diminishing personal biases and presumptions to provide a more transparent and accurate understanding of the real risks involved. Survey responses from 16 practitioners working in the private and public sectors confirmed the validity of the approach but suggest it may be more workable in larger organisations where resources allow dedicated risk professionals to operate. This research contributes to the literature on IT and cyber risk management and provides new perspectives on the need to improve objectivity in asset valuation and risk assessment.
引用
收藏
页数:27
相关论文
共 50 条
  • [41] Cyber Security Risk Management: E-Learning System
    AlMufairej, AlAnoud
    BinGhaith, Lama
    AlShareef, Deena
    Jamail, Nor Shahida Mohd
    2022 FIFTH INTERNATIONAL CONFERENCE OF WOMEN IN DATA SCIENCE AT PRINCE SULTAN UNIVERSITY (WIDS-PSU 2022), 2022, : 146 - 149
  • [42] An Approach for Risk Management of Computer Security Base on Polling System
    Hashemi, Seyed Mahmood
    He, Jingsha
    2015 IEEE 16TH INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY (ICCT), 2015, : 912 - 918
  • [43] Introduction of a Corporate Security Risk Management System: The Experience of Poland
    Kalina, Iryna
    Khurdei, Viktoriia
    Shevchuk, Vira
    Vlasiuk, Tetiana
    Leonidov, Ihor
    JOURNAL OF RISK AND FINANCIAL MANAGEMENT, 2022, 15 (08)
  • [44] Research of Information System Security Risk Management based on Probability Model and Security Entropy
    Du, Jiawei
    Zhou, Ying
    Guo, Ronghua
    Zhang, Xing
    Suo, Guowei
    INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND APPLICATION ENGINEERING (CSAE), 2017, 190 : 414 - 420
  • [45] Towards Context-Aware Supervision for Logistics Asset Management: Concept Design and System Implementation
    Feng, Fan
    Pang, Yusong
    Lodewijks, Gabriel
    INFORMATION TECHNOLOGY FOR MANAGEMENT: NEW IDEAS AND REAL SOLUTIONS, 2017, 277 : 3 - 19
  • [46] RESEARCH ON THE EVALUATION INDEX SYSTEM OF THE RISK MANAGEMENT LEVEL OF ASSET MANAGEMENT OF CHINA'S COMMERCIAL BANKS
    Fang, Yinjie
    Liu, Shiran
    ECONOMICS, FINANCE AND STATISTICS, VOL 2, ISSUE 1, 2018, : 48 - 51
  • [47] Risk assessment method based on business process-oriented asset evaluation for information system security
    Eom, Jung-Ho
    Park, Seon-Ho
    Han, Young-Ju
    Chung, Tai-Myoung
    COMPUTATIONAL SCIENCE - ICCS 2007, PT 3, PROCEEDINGS, 2007, 4489 : 1024 - +
  • [48] Using risk-informed asset management for feedwater system preventative maintenance optimization
    Kee, E
    Sun, A
    Richards, A
    Liming, J
    Salter, J
    Grantom, R
    JOURNAL OF NUCLEAR SCIENCE AND TECHNOLOGY, 2004, 41 (03) : 347 - 353
  • [49] Design of a Federated Learning System for IT Security: Towards Secure Human Resource Management
    Verlande, Lisa
    Rudel, Steffi
    Lechner, Ulrike
    PROCEEDINGS OF 2022 11TH LATIN-AMERICAN SYMPOSIUM ON DEPENDABLE COMPUTING, LADC 2022, 2022, : 131 - 136
  • [50] Anomaly Detection System Towards a framework for enterprise log management of security services
    Ozulku, Omer
    Fadhel, Nawfal F.
    Argles, David
    Wills, Gary B.
    2014 WORLD CONGRESS ON INTERNET SECURITY (WORLDCIS), 2014, : 97 - 102