• DocumentCode
    1996332
  • Title

    Information assets security requirement: The relationship between confidentiality and availability of information assets in ICT outsourcing

  • Author

    Khidzir, N.Z. ; Mohamed, Amr ; Arshad, N.H.H.

  • Author_Institution
    Sch. of Inf. Technol. Infrastruct., Infrastruct. Univ. Kuala Lumpur, Bangi, Malaysia
  • fYear
    2012
  • fDate
    3-4 Dec. 2012
  • Firstpage
    193
  • Lastpage
    197
  • Abstract
    Information Communication Technology (ICT) Outsourcing provides an effective ways to cut cost and improve efficiency in ICT services. However, the strategy could invite some risks including information security risk. Therefore, fundamental concepts of information security requirements such as confidentiality, integrity and availability for information assets involved in ICT outsourcing cycle need to be identified extensively to ensure these information assets are secure from security risks. Hence, the main objective of this research is to conduct an empirical study on relationship between information assets confidentiality and availability in ICT outsourcing. Questionnaires were distributed to 300 private companies from various industry and government agencies in Malaysia for the study. Findings reveal that the higher the confidentiality level, the higher the availability level of the information assets. However, the findings revealed dissimilar relationship strength between confidentiality and availability of information assets in ICT outsourcing phases. Strong positive relationship exists between confidentiality and availability in Selection of Service Provider and On-going Monitoring phase. But, moderate positive relationship exists in Analysis of Decision to Outsource and Contract Management phases. Based from these findings, organization could improve their plan and practices in managing information assets and to urgently address information security risks in ICT outsourcing project implementation.
  • Keywords
    DP management; information management; outsourcing; security of data; ICT outsourcing; ICT service; Malaysia; information and communication technology; information asset availability; information asset confidentiality; information asset integrity; information asset security requirement; information security risk; outsource decision analysis; service provider monitoring phase; service provider selection; Availability; Confidentiality; ICT Outsourcing; Information Asset; Information Security Requirement;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Humanities, Science and Engineering (CHUSER), 2012 IEEE Colloquium on
  • Conference_Location
    Kota Kinabalu
  • Print_ISBN
    978-1-4673-4615-3
  • Type

    conf

  • DOI
    10.1109/CHUSER.2012.6504309
  • Filename
    6504309