2008
DOI: 10.28945/996
|View full text |Cite
|
Sign up to set email alerts
|

Improving Information Security Risk Analysis Practices for Small- and Medium-Sized Enterprises:  A Research Agenda

Abstract: Despite the availability of numerous methods and publications concerning the proper conduct of information security risk analyses, small and medium sized enterprises (SMEs) face serious organizational challenges managing the deployment and use of these tools and methods to assist them in selecting and implementing security safeguards to prevent IS security compromises. This paper builds a case for and then outlines a possible approach and a multi-faceted research agenda for developing an " open development" st… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
23
0

Year Published

2012
2012
2022
2022

Publication Types

Select...
2
2
1

Relationship

0
5

Authors

Journals

citations
Cited by 9 publications
(23 citation statements)
references
References 10 publications
(12 reference statements)
0
23
0
Order By: Relevance
“…Research in information security indicates that small-scale organisations seldom deploy proper information security controls regardless of the availability of guidelines to this effect (Dimopoulos, Furnell & Barlow, 2003;Beachboard et al 2008). Management in small-scale organisations are prepared to invest more resources in protecting computing infrastructure without assessing the risks to their critical information (Dimopoulos et al 2003;Panda, 2009).…”
Section: Information Securitymentioning
confidence: 99%
See 3 more Smart Citations
“…Research in information security indicates that small-scale organisations seldom deploy proper information security controls regardless of the availability of guidelines to this effect (Dimopoulos, Furnell & Barlow, 2003;Beachboard et al 2008). Management in small-scale organisations are prepared to invest more resources in protecting computing infrastructure without assessing the risks to their critical information (Dimopoulos et al 2003;Panda, 2009).…”
Section: Information Securitymentioning
confidence: 99%
“…Risk management is an iterative process with well-defined steps, which when taken in sequence, supports better decision-making by contributing a greater insight into risks and their impacts (Hoo, 2000). Large organisations include their risk management plans in their security policies (Alberts & Dorofee, 2001;Beachboard et al 2008). This is different from small-scale organisations such as secondary schools that may have problems in formulating workable risk management plans and fail to implement them.…”
Section: Risk Managementmentioning
confidence: 99%
See 2 more Smart Citations
“…Small companies and organizations expose themselves to risk in believing that their data are not of interest to cybercriminals. External attacks are beginning to occur among smaller organizations as they often have relationships or host systems with their larger counterparts, and larger organizations are more likely to have the means to provide a more advanced information security system (Beachboard et al., ; White, ). Although large organizations usually have more advanced information security measures in place, their security functions within their organizational structure often undergo frequent change (Johnson & Goetz, ).…”
Section: Introductionmentioning
confidence: 99%