A Framework for Managing Security Risks of Outsourced IT Projects: An Empirical Study

被引:3
|
作者
Almutairi, Moneef [1 ]
Riddle, Stephen [1 ]
机构
[1] Newcastle Univ, Sch Comp Sci, Newcastle Upon Tyne, Tyne & Wear, England
关键词
Security Management; IT project framework; empirical study;
D O I
10.1145/3178461.3178476
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Several firms outsource their IT services partially or totally due to different constraints such as business, financial or legal. Although IT outsourcing has tremendous benefits such as cost reduction, it might expose firms to different security risks including confidentiality, integrity, and availability issues. In this paper, we present the evaluation results for a proposed framework that we developed previously for managing the security and compliance risks of outsourced IT projects. The evaluation is designed to assess several features of the proposed framework. Usefulness, flexibility, simplicity and ease of use as well as achieving a systematic and comprehensive methodology for managing the security and compliance risks of outsourced IT projects are evaluated in this paper. Additionally, we evaluate the usefulness of utilizing project phases and the proposed threat classification approach for identifying and managing security threats in the outsourcing context. Finally, we evaluate the ability of the proposed framework to be applied to any project regardless of project size, cost, or any other constraints.
引用
收藏
页码:40 / 44
页数:5
相关论文
共 50 条
  • [21] A Life-Cycle Framework for Managing Risks in Public Private Partnership Housing Projects
    Sanda Y.N.
    Anigbogu N.A.
    Nuhu L.Y.
    Olumide O.S.
    [J]. Journal of Engineering, Project, and Production Management, 2020, 10 (01) : 27 - 34
  • [22] Outsourced IT projects from the vendor perspective: Different goals, different risks
    Taylor, Hazel
    [J]. JOURNAL OF GLOBAL INFORMATION MANAGEMENT, 2007, 15 (02) : 1 - 27
  • [23] Managing the risks of intranet implementation: an empirical study of user satisfaction
    Phelps, R
    Mok, M
    [J]. JOURNAL OF INFORMATION TECHNOLOGY, 1999, 14 (01) : 39 - 52
  • [24] Managing Outsourced Software Projects: An Analysis of Project Performance and Customer Satisfaction
    Narayanan, Sriram
    Balasubramanian, Sridhar
    Swaminathan, Jayashankar M.
    [J]. PRODUCTION AND OPERATIONS MANAGEMENT, 2011, 20 (04) : 508 - 521
  • [25] MANAGING RISKS: A NEW FRAMEWORK
    Kaplan, Robert S.
    Mikes, Anette
    [J]. HARVARD BUSINESS REVIEW, 2012, 90 (06) : 48 - 58
  • [26] An Empirical Study of Security Issues Posted in Open Source Projects
    Zahedi, Mansooreh
    Babar, Muhammad Ali
    Treude, Christoph
    [J]. PROCEEDINGS OF THE 51ST ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES (HICSS), 2018, : 5504 - 5513
  • [27] URBAN WATER SECURITY: MANAGING RISKS
    Bonacci, Ognjen
    [J]. HRVATSKE VODE, 2010, 18 (74) : 366 - 368
  • [28] MANAGING TRANSPORTATION SAFETY AND SECURITY RISKS
    Fuller, Brad A.
    [J]. CHEMICAL ENGINEERING PROGRESS, 2009, 105 (10) : 23 - 27
  • [29] MITIGATING AND MANAGING RISKS IN MOBILE TELECOM PROJECTS
    Eid, M. Mostafa
    Georgy, Maged
    Osman, Hesham
    Ibrahim, Moheeb
    [J]. IMPLEMENTING INNOVATIVE IDEAS IN STRUCTURAL ENGINEERING AND PROJECT MANAGEMENT, 2015, : 857 - 862
  • [30] A Layered Approach to Managing Risks in OSS Projects
    Franch, Xavier
    Kenett, Ron
    Mancinelli, Fabio
    Susi, Angelo
    Ameller, David
    Ben-Jacob, Ron
    Siena, Alberto
    [J]. OPEN SOURCE SOFTWARE: MOBILE OPEN SOURCE TECHNOLOGIES, 2014, 427 : 168 - 171