2009
DOI: 10.1016/j.ijcip.2009.02.004
|View full text |Cite
|
Sign up to set email alerts
|

A framework for incident response management in the petroleum industry

Abstract: Process control systems Learning Security culture A B S T R A C TIncident response is the process of responding to and handling security-related incidents involving information and communications technology (ICT) infrastructure and data.Incident response has traditionally been reactive in nature, focusing mainly on technical issues. This paper presents the Incident Response Management (IRMA) method, which combines traditional incident response with proactive learning and socio-technical perspectives. The IRMA … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
2

Citation Types

0
32
0

Year Published

2011
2011
2019
2019

Publication Types

Select...
5
2

Relationship

2
5

Authors

Journals

citations
Cited by 46 publications
(32 citation statements)
references
References 20 publications
0
32
0
Order By: Relevance
“…Several researchers focused on how current approaches do not adequately support security incident learning (Ahmad et al, 2012;Shedden et al, 2010Shedden et al, , 2011Tan et al, 2003;Jaatun et al, 2009). Ahmad et al (2012) argue that the 'feedback' phase is often skipped because security incident response teams are too focused on containment, eradication, and recovery.…”
Section: Related Workmentioning
confidence: 99%
See 2 more Smart Citations
“…Several researchers focused on how current approaches do not adequately support security incident learning (Ahmad et al, 2012;Shedden et al, 2010Shedden et al, , 2011Tan et al, 2003;Jaatun et al, 2009). Ahmad et al (2012) argue that the 'feedback' phase is often skipped because security incident response teams are too focused on containment, eradication, and recovery.…”
Section: Related Workmentioning
confidence: 99%
“…Ahmad et al (2012) argue that the 'feedback' phase is often skipped because security incident response teams are too focused on containment, eradication, and recovery. In a study involving the petroleum industry, Jaatun et al (2009) explained that while learning from security incidents was considered important, organizations found it difficult to implement the concept in practice. Jaatun et al (2009) go on to argue that organizations must be prepared for incident learning and this includes obtaining managerial commitment and the willingness to commit resources to facilitate learning from security incidents.…”
Section: Related Workmentioning
confidence: 99%
See 1 more Smart Citation
“…Creating adequate plans for incident handling: Having a simple, short and common plan for incident management was recommended by Jaatun et al (2009) and Cusick and Ma (2010). This was considered an advantage when present and a need when not present.…”
Section: Information Security Incident Managementmentioning
confidence: 99%
“…This was considered an advantage when present and a need when not present. Without it, the approach to incident management could appear scattered and randomly structured (Jaatun et al, 2009). A lack of plans was reported by Line et al (2014) to hinder training activities, as a plan was perceived as needed as a basis for training.…”
Section: Information Security Incident Managementmentioning
confidence: 99%