2016
DOI: 10.1016/j.cose.2016.05.004
|View full text |Cite
|
Sign up to set email alerts
|

The future of information security incident management training: A case study of electrical power companies

Abstract: Recent attacks and threat reports indicate that industrial control organizations are attractive targets for attacks. Emerging threats create the need for a well-established capacity for responding to unwanted incidents. Such a capacity is influenced by organizational, human, and technological factors. We have conducted extensive fieldwork for 2.5 years in Norwegian electric power companies with the aim of identifying challenges for improving information security incident management practices. Semi-structured i… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

1
9
0
1

Year Published

2016
2016
2020
2020

Publication Types

Select...
5
2

Relationship

2
5

Authors

Journals

citations
Cited by 29 publications
(14 citation statements)
references
References 34 publications
(46 reference statements)
1
9
0
1
Order By: Relevance
“…The results of this study support the research of Bartnes et al (2016) who say that learning will enable organizations to improve response practices for incidents. Mattia (2011) said learning can help organizations to adapt and manage the process of securing organizational assets, and Kovacich (2016) states that system security is one of the fastest growing things now, the internet as a core infrastructure is the target of attacks, so organizations must have knowledge which is good for dealing with cyber-attacks through learning.…”
Section: Conclusion and Recommendationssupporting
confidence: 83%
“…The results of this study support the research of Bartnes et al (2016) who say that learning will enable organizations to improve response practices for incidents. Mattia (2011) said learning can help organizations to adapt and manage the process of securing organizational assets, and Kovacich (2016) states that system security is one of the fastest growing things now, the internet as a core infrastructure is the target of attacks, so organizations must have knowledge which is good for dealing with cyber-attacks through learning.…”
Section: Conclusion and Recommendationssupporting
confidence: 83%
“…Algunos autores prefieren diseñar sus casos de estudio utilizando la metodología de investigación de Yin (2009). Bartnes & Brede (2016) presentaron su investigación utilizando la recopilación de datos, el análisis de datos, las secciones de escenarios y contenido de casos. Meszaros & Buchalcevova (2016) diseñaron el Marco de Seguridad de Servicios Online (OSSF) y sus métodos de investigación se organizaron en un proceso con las siguientes actividades:…”
Section: Metodologíaunclassified
“…The specific nature of the assistance required depends on both the technical and business impact of the threat. To understand the gaps in the knowledge and how to design the organization to support the response unit, organizations need to perform exercises frequently and evaluate their outcome (Bartnes et al, 2016).…”
Section: Tabletop Exercisesmentioning
confidence: 99%