2020
DOI: 10.1371/journal.pone.0238739
|View full text |Cite
|
Sign up to set email alerts
|

A real-world information security performance assessment using a multidimensional socio-technical approach

Abstract: Measuring the performance of information security is an essential part of the information security management system within organisations. Studies in the past mainly focused on establishing qualitative measurement approaches. Since these can lead to ambiguous conclusions, quantitative metrics are being increasingly proposed as a useful alternative. Nevertheless, the literature on quantitative approaches remains scarce. Thus, studies on the evaluation of information security performance are challenging, especia… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
7
0
4

Year Published

2021
2021
2023
2023

Publication Types

Select...
5
2

Relationship

0
7

Authors

Journals

citations
Cited by 15 publications
(11 citation statements)
references
References 61 publications
0
7
0
4
Order By: Relevance
“…As research shows [e.g. 47 , 48 ] the family-friendly work environment and safety concerns are an important factor in work engagement. Research [ 2 , 49 , 50 ] has also shown that the length of working time also plays an important role in reconciling work and family life, as those employees who have a longer working day have greater difficulties in work-life balance.…”
Section: Introductionmentioning
confidence: 99%
“…As research shows [e.g. 47 , 48 ] the family-friendly work environment and safety concerns are an important factor in work engagement. Research [ 2 , 49 , 50 ] has also shown that the length of working time also plays an important role in reconciling work and family life, as those employees who have a longer working day have greater difficulties in work-life balance.…”
Section: Introductionmentioning
confidence: 99%
“…How people can assess information security for public administration requires a systematic approach that increases based on the needs of continuous improvement [37]. The evaluation model developed by Zuo [38] can be used as a benchmark accompanied by a socio-technical multidimensional approach [39]. The audit implementation relies on advanced standards and frameworks of IT infrastructure organization, management, and security such as Cobit and ISO 17799 [40].…”
Section: Discussionmentioning
confidence: 99%
“…Pomanjkanje ustrezne informacijske varnosti lahko vodi v izgubo dobička in slab ugled organizacije (Roy Sarkar, 2010). Da bi dobili vpogled v dejansko stanje informacijske varnosti moramo implementirati ustrezne merilne mehanizme (Prislan et al, 2020), kot so kvantitativne in kvalitativne metrike (Fujs et al, 2020(Fujs et al, , 2019. Informacijska varnost se je tradicionalno zago-tavljala s pomočjo tehničnih varnostnih mehanizmov (kot so npr.…”
Section: Uvodunclassified