Title of article :
Incident-centered information security: Managing a strategic balance between prevention and response
Author/Authors :
Richard Baskerville، نويسنده , , Paolo Spagnoletti، نويسنده , , Jongwoo Kim، نويسنده ,
Issue Information :
روزنامه با شماره پیاپی سال 2014
Pages :
14
From page :
138
To page :
151
Abstract :
Information security strategies employ principles and practices grounded in both the prevention and response paradigms. The prevention paradigm aims at managing predicted threats. Although the prevention paradigm may dominate in contemporary commercial organizations, the response paradigm (aimed at managing unpredicted threats) retains an important role in protecting information security in todayʹs dynamic threat environment. This study provides an overarching security framework that focuses on managing the proper balance between prevention and response paradigms. We conduct a comparative case study with three European organizations. This study analyzes and empirically confirms how and why organizations balance between their prevention and response strategies.
Keywords :
Response paradigm , Security balance , CASE STUDY , Prevention paradigm , Information security management , Incident-centered analysis
Journal title :
Information and Management
Serial Year :
2014
Journal title :
Information and Management
Record number :
1227129
Link To Document :
بازگشت