DocumentCode :
1996332
Title :
Information assets security requirement: The relationship between confidentiality and availability of information assets in ICT outsourcing
Author :
Khidzir, N.Z. ; Mohamed, Amr ; Arshad, N.H.H.
Author_Institution :
Sch. of Inf. Technol. Infrastruct., Infrastruct. Univ. Kuala Lumpur, Bangi, Malaysia
fYear :
2012
fDate :
3-4 Dec. 2012
Firstpage :
193
Lastpage :
197
Abstract :
Information Communication Technology (ICT) Outsourcing provides an effective ways to cut cost and improve efficiency in ICT services. However, the strategy could invite some risks including information security risk. Therefore, fundamental concepts of information security requirements such as confidentiality, integrity and availability for information assets involved in ICT outsourcing cycle need to be identified extensively to ensure these information assets are secure from security risks. Hence, the main objective of this research is to conduct an empirical study on relationship between information assets confidentiality and availability in ICT outsourcing. Questionnaires were distributed to 300 private companies from various industry and government agencies in Malaysia for the study. Findings reveal that the higher the confidentiality level, the higher the availability level of the information assets. However, the findings revealed dissimilar relationship strength between confidentiality and availability of information assets in ICT outsourcing phases. Strong positive relationship exists between confidentiality and availability in Selection of Service Provider and On-going Monitoring phase. But, moderate positive relationship exists in Analysis of Decision to Outsource and Contract Management phases. Based from these findings, organization could improve their plan and practices in managing information assets and to urgently address information security risks in ICT outsourcing project implementation.
Keywords :
DP management; information management; outsourcing; security of data; ICT outsourcing; ICT service; Malaysia; information and communication technology; information asset availability; information asset confidentiality; information asset integrity; information asset security requirement; information security risk; outsource decision analysis; service provider monitoring phase; service provider selection; Availability; Confidentiality; ICT Outsourcing; Information Asset; Information Security Requirement;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Humanities, Science and Engineering (CHUSER), 2012 IEEE Colloquium on
Conference_Location :
Kota Kinabalu
Print_ISBN :
978-1-4673-4615-3
Type :
conf
DOI :
10.1109/CHUSER.2012.6504309
Filename :
6504309
Link To Document :
بازگشت