Understanding user participation in information security risk management

Risk management is the continuing process to control and manage the risk in organisation for identifying, accessing and controlling threats to an organisation’s capital and earning. The implementation of information security risk management (ISRM) helps to address the risks to information processed...

全面介紹

Saved in:
書目詳細資料
Main Authors: Mat Deli, Mohd. Sharudin, Ahmad, Jarin Fathima, Hassan, Noor Hafizah, Maarop, Nurazean, Samy, Ganthan Narayana, Abdullah, Mohd. Shahidan, Yaacob, Suraya
格式: Article
語言:English
出版: Advanced Informatics School, Universiti Teknologi Malaysia 2017
主題:
在線閱讀:http://eprints.utm.my/id/eprint/80684/1/NoorHafizahHassan2017_UnderstandingUserParticipationinInformation.pdf
http://eprints.utm.my/id/eprint/80684/
http://publication.ais.utm.my/ojs/index.php/oiji/article/view/35/18
標簽: 添加標簽
沒有標簽, 成為第一個標記此記錄!
實物特徵
總結:Risk management is the continuing process to control and manage the risk in organisation for identifying, accessing and controlling threats to an organisation’s capital and earning. The implementation of information security risk management (ISRM) helps to address the risks to information processed by an organisation that may help the organisation to manage the risk effectively. Involving the user throughout the process of ISRM is important to ensure that it provides an effective security risk management (SRM). There are limited evidence shows that user participation is important in ISRM. Therefore, the aim of this paper to investigate user participation in ISRM from user participation and access control constructs. A quantitative method is implemented by distributing a questionnaire to two different organisational backgrounds to 20 respondents. This paper presents the initial findings that user participation play a significant role towards ISRM by presenting the results from the two constructs. The findings contribute to the body of knowledge that understanding user participation in ISRM shows that the process of risk management is different between two organisational backgrounds.