How integration of cyber security management and incident response enables organizational learning
Ahmad, Atif, Desouza, Kevin C., Maynard, Sean B., Naseer, Humza, & Baskerville, Richard L. (2020) How integration of cyber security management and incident response enables organizational learning. Journal of the Association for Information Science and Technology, 71(8), pp. 939-953.
|
Accepted Version
(PDF 676kB)
59652368. Available under License Creative Commons Attribution Non-commercial 4.0. |
Description
Digital assets of organizations are under constant threat from a wide assortment of nefarious actors. When threats materialize, the consequences can be significant. Most large organizations invest in a dedicated information security management (ISM) function to ensure that digital assets are protected. The ISM function conducts risk assessments, develops strategy, provides policies and training to define roles and guide behavior, and implements technological controls such as firewalls, antivirus, and encryption to restrict unauthorized access. Despite these protective measures, incidents (security breaches) will occur. Alongside the security management function, many organizations also retain an incident response (IR) function to mitigate damage from an attack and promptly restore digital services. However, few organizations integrate and learn from experiences of these functions in an optimal manner that enables them to not only respond to security incidents, but also proactively maneuver the threat environment. In this article we draw on organizational learning theory to develop a conceptual framework that explains how the ISM and IR functions can be better integrated. The strong integration of ISM and IR functions, in turn, creates learning opportunities that lead to organizational security benefits including: increased awareness of security risks, compilation of threat intelligence, removal of flaws in security defenses, evaluation of security defensive logic, and enhanced security response.
Impact and interest:
Citation counts are sourced monthly from Scopus and Web of Science® citation databases.
These databases contain citations from different subsets of available publications and different time periods and thus the citation count from each is usually different. Some works are not in either database and no count is displayed. Scopus includes citations from articles published in 1996 onwards, and Web of Science® generally from 1980 onwards.
Citations counts from the Google Scholar™ indexing service can be viewed at the linked Google Scholar™ search.
Full-text downloads:
Full-text downloads displays the total number of times this work’s files (e.g., a PDF) have been downloaded from QUT ePrints as well as the number of downloads in the previous 365 days. The count includes downloads for all files if a work has more than one.
ID Code: | 201843 | ||
---|---|---|---|
Item Type: | Contribution to Journal (Journal Article) | ||
Refereed: | Yes | ||
ORCID iD: |
|
||
Measurements or Duration: | 15 pages | ||
DOI: | 10.1002/asi.24311 | ||
ISSN: | 2330-1635 | ||
Pure ID: | 59652368 | ||
Divisions: | Current > Research Centres > Centre for Future Enterprise Current > Research Centres > Centre for Data Science Past > QUT Faculties & Divisions > QUT Business School Past > Institutes > Institute for Future Environments Current > QUT Faculties and Divisions > Faculty of Business & Law Current > Schools > School of Management Current > QUT Faculties and Divisions > Faculty of Science Current > Research Centres > Centre for Tropical Crops and Biocommodities |
||
Copyright Owner: | 2019 ASIS&T | ||
Copyright Statement: | This work is covered by copyright. Unless the document is being made available under a Creative Commons Licence, you must assume that re-use is limited to personal use and that permission from the copyright owner must be obtained for all other uses. If the document is available under a Creative Commons License (or other specified license) then refer to the Licence for details of permitted re-use. It is a condition of access that users recognise and abide by the legal requirements associated with these rights. If you believe that this work infringes copyright please provide details by email to [email protected] | ||
Deposited On: | 10 Jul 2020 01:07 | ||
Last Modified: | 14 Apr 2025 14:45 |
Export: EndNote | Dublin Core | BibTeX
Repository Staff Only: item control page