A Framework for Managing Security Risks of Outsourced IT Projects: An Empirical Study

被引:3
|
作者
Almutairi, Moneef [1 ]
Riddle, Stephen [1 ]
机构
[1] Newcastle Univ, Sch Comp Sci, Newcastle Upon Tyne, Tyne & Wear, England
关键词
Security Management; IT project framework; empirical study;
D O I
10.1145/3178461.3178476
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Several firms outsource their IT services partially or totally due to different constraints such as business, financial or legal. Although IT outsourcing has tremendous benefits such as cost reduction, it might expose firms to different security risks including confidentiality, integrity, and availability issues. In this paper, we present the evaluation results for a proposed framework that we developed previously for managing the security and compliance risks of outsourced IT projects. The evaluation is designed to assess several features of the proposed framework. Usefulness, flexibility, simplicity and ease of use as well as achieving a systematic and comprehensive methodology for managing the security and compliance risks of outsourced IT projects are evaluated in this paper. Additionally, we evaluate the usefulness of utilizing project phases and the proposed threat classification approach for identifying and managing security threats in the outsourcing context. Finally, we evaluate the ability of the proposed framework to be applied to any project regardless of project size, cost, or any other constraints.
引用
收藏
页码:40 / 44
页数:5
相关论文
共 50 条
  • [1] Managing Outsourced IT Projects' Security Risks: A Case Study
    Almutairi, Moneef
    Riddle, Stephen
    [J]. ICIME 2018: PROCEEDINGS OF THE 2018 10TH INTERNATIONAL CONFERENCE ON INFORMATION MANAGEMENT AND ENGINEERING, 2018, : 21 - 26
  • [2] Offshoring IT Services: A Framework for Managing Outsourced Projects
    Lo, Henry
    [J]. ELECTRONIC JOURNAL OF INFORMATION SYSTEMS IN DEVELOPING COUNTRIES, 2006, 24 (01):
  • [3] Managing outsourced automation projects
    Pageler, EL
    [J]. I&CS-INSTRUMENTATION & CONTROL SYSTEMS, 1996, 69 (05): : 27 - 31
  • [4] Risks and Hidden Costs: A Study of 26 Outsourced Projects
    Haddad, Maliha
    [J]. AMCIS 2010 PROCEEDINGS, 2010,
  • [5] Managing Risks in Distributed Software Projects: An Integrative Framework
    Persson, John Stouby
    Mathiassen, Lars
    Boeg, Jesper
    Madsen, Thomas Stenskrog
    Steinson, Flemming
    [J]. IEEE TRANSACTIONS ON ENGINEERING MANAGEMENT, 2009, 56 (03) : 508 - 532
  • [6] Security Threat Classification For Outsourced IT Projects
    Almutairi, Moneef
    Riddle, Stephen
    [J]. 2017 11TH INTERNATIONAL CONFERENCE ON RESEARCH CHALLENGES IN INFORMATION SCIENCE (RCIS), 2017, : 447 - 448
  • [7] Managing quality in projects: An empirical study
    Basu, Ron
    [J]. INTERNATIONAL JOURNAL OF PROJECT MANAGEMENT, 2014, 32 (01) : 178 - 187
  • [8] Critical risks in outsourced IT projects: The intractable and the unforeseen
    Taylor, Hazel
    [J]. COMMUNICATIONS OF THE ACM, 2006, 49 (11) : 75 - 79
  • [9] A Structured Framework for Managing Offshore Outsourcing Risks on Software Support Projects
    Lascano, Natacha
    Maniasi, Sebastian
    Colla, Pedro
    [J]. SOFTWARE ENGINEERING APPROACHES FOR OFFSHORE AND OUTSOURCED DEVELOPMENT, 2010, 54 : 87 - +
  • [10] Managing Security Risks
    Abrahamson, Donald W.
    Sepeda, Adrian L.
    [J]. CHEMICAL ENGINEERING PROGRESS, 2009, 105 (07) : 41 - 47