Decision-Making by Effective Information Security Managers

被引:0
|
作者
Pettigrew, James [1 ]
Ryan, Julie [1 ]
Salous, Kyle [1 ]
Mazzuchi, Thomas [1 ]
机构
[1] George Washington Univ, Washington, DC 20052 USA
关键词
Information security management; decision-making; open-interview;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
A pilot study was conducted in the last half of 2009 exploring how responsible managers make decisions with regards to information security in the enterprise. This pilot study is part of a larger research effort focused on exploring this topic. This is an interesting problem to study because security managers must make decisions based on instinct and experience rather than empirical security performance data. Yet some of the security managers are doing a decent job despite the lack of any empirical data. They face daily decisions on a variety of issues dealing with maintaining and improving the security integrity of their enterprises. While this is a constant problem confronting these managers, many are very successful. These effective managers, recognized by reputation, community and anecdotally, have ways of measuring effectiveness. However, these measures are more art and the data is only in the heads of the managers. Exploratory research was conducted to validate a method to explore how security managers make decisions about the allocation of security resources for their enterprise information security architectures. This paper presents the initial findings from the pilot study. The subjects of this pilot study were the Chief Technology and Chief Security Officers (CTO and CSO) of a large enterprise. The research method used was open-ended interviews followed by transcript analysis and categorization. The interview transcripts were analyzed to identify important themes and processes resulting in twenty-three categories of decision influences. While all categories are defined, five were common to the CTO and CSO and are highlighted. A key finding is that while the CTO and CSO share some concerns, they also have unique perspectives. This will be explored in future research from the perspective of effective team building for enterprise security management. The results of this pilot study will be used to compose a larger research effort to explore and document decision processes for successful security managers.
引用
收藏
页码:465 / 472
页数:8
相关论文
共 50 条