Security risks in service offshoring and outsourcing

被引:25
|
作者
Nassimbeni, Guido [1 ]
Sartor, Marco [1 ]
Dus, Daiana [2 ]
机构
[1] Univ Udine, I-33100 Udine, Italy
[2] Univ Turin, CASSCC, Turin, Italy
关键词
Service industries; Outsourcing; Data security; Knowledge management; Security risks; Offshoring; Failure mode and effect analysis; INTELLECTUAL PROPERTY PROTECTION; ANALYTIC HIERARCHY PROCESS; INFORMATION-SYSTEMS; BUSINESS PROCESS; KNOWLEDGE; GOVERNANCE; INVESTMENT; MANAGEMENT; MODEL; ENTRY;
D O I
10.1108/02635571211210059
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Purpose Service outsourcing/offshoring represents an increasing phenomenon. Several factors (e.g. cost reduction, flexibility, access to new technologies and skills, access to new markets, focus on core activities) motivate the location of (IT or business) processes abroad and/or out of the companies' boundaries. This choice determines also relevant risks. Knowledge and data protection constitutes one of the most relevant issues in service outsourcing/offshoring because it can strongly affect the success of these projects. The purpose of this paper is to propose an assessment framework that highlights the main risks of offshoring and outsourcing projects. Design/methodology/approach Building on the model developed by Monczka of at (2005), this work proposes a FMEA assessment framework that highlights the main risks of offshoring and outsourcing projects, their causes, effects and some possible (preventing/correcting) actions. The proposed framework has been implemented and tested in a multinational company for a long time involved in service offshoring/outsourcing projects. Findings Adopting a failure mode and effect analysis (FMEA) approach, the study describes the main possible failures, their causes, effects and possible (preventive and corrective) actions, along all of the phases of typical outsourcing/offshoring projects. Originality/value The paper develops an assessment framework able to identify the security risk profile of companies engaged in outsourcing/offshoring projects by considering the technical, legal and managerial aspects jointly; and detecting the causes of possible security failures and the related preventive and corrective actions.
引用
收藏
页码:405 / 440
页数:36
相关论文
共 50 条
  • [31] State of the Art of IT Outsourcing and Future Needs for Managing Its Security Risks
    Almutairi, Moneef
    Riddle, Stephen
    2018 INTERNATIONAL CONFERENCE ON INFORMATION MANAGEMENT AND PROCESSING (ICIMP 2018), 2018, : 42 - 48
  • [32] The risks of outsourcing IT
    Earl, MJ
    SLOAN MANAGEMENT REVIEW, 1996, 37 (03): : 26 - 32
  • [33] Risks of outsourcing IT
    Phillips, AP
    SLOAN MANAGEMENT REVIEW, 1996, 37 (04): : 8 - 8
  • [34] A Security Assessment Framework and Selection Method for Outsourcing Cloud Service
    Liu, Xiaochen
    Xia, Chunhe
    Cao, Jiajin
    Gao, Jinghua
    Wei, Zhao
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2014, 8 (06): : 375 - 388
  • [35] Offshoring of Service Jobs
    Demiroglu, Ufuk
    CENTRAL BANK REVIEW, 2008, 8 (01) : 17 - 63
  • [36] Analysis of risks faced by information technology offshore outsourcing service providers
    Ahmed, Faheem
    Capretz, Luiz Fernando
    Sandhu, Maqsood Ahmad
    Raza, Arif
    IET SOFTWARE, 2014, 8 (06) : 279 - 284
  • [37] Solutions for customer complaints about offshoring and outsourcing services
    Honeycutt, Earl D., Jr.
    Magnini, Vincent P.
    Thelen, Shawn T.
    BUSINESS HORIZONS, 2012, 55 (01) : 33 - 42
  • [38] Offshoring and outsourcing the 'unauthorised': The annual reports of an anxious state
    Andrew, Jane
    Eden, Dave
    POLICY AND SOCIETY, 2011, 30 (03) : 221 - 234
  • [39] Mass layoff data indicate outsourcing and offshoring work
    Brown, SP
    Siegel, LB
    MONTHLY LABOR REVIEW, 2005, 128 (08) : 3 - 10
  • [40] Outsourcing and Offshoring Under the General Agreement on Trade in Services
    Lapid, Karen
    JOURNAL OF WORLD TRADE, 2006, 40 (02) : 341 - 364