The Experts below are selected from a list of 42798 Experts worldwide ranked by ideXlab platform
Jia Wei-guo - One of the best experts on this subject based on the ideXlab platform.
-
Discussion on the Network Information Security Risk Assessment Work In the Military Academy
Computers & Security, 2009Co-Authors: Jia Wei-guoAbstract:In order to strengthen the Security management of the network Information system of the military academy further,it is going necessary to carry out the network Information Security Risk assessment work of the military academy overall and regularly.Combining with the investigation of the work of the Information network Security management in the military academy,this paper discusses the related problems of the Security Risk assessment of the network Information from the technique and the management angles;analyzes and summarizes the misunderstandings and the main problems of the network Information Security Risk assessment work of military academy;proposes the new way that can resolve the extant problems of the work.
Nik Zulkarnaen Khidzir - One of the best experts on this subject based on the ideXlab platform.
-
Information Security Risk factors and management framework for ICT outsourcing / Nik Zulkarnaen Khidzir
2013Co-Authors: Nik Zulkarnaen KhidzirAbstract:Information Communication Technology (ICT) services have become increasingly important in today’s business environment with most private and government agencies without sufficient resources and expertise outsourcing their ICT projects to vendors. However, this strategy could invite potentially damaging Information Security Risks (ISRs). Subsequently, a dedicated framework for Information Security Risk management for ICT outsourcing activities needs to be in place to address and manage its related Risk factors. The research focuses on managing Information Security Risks (ISRs) in ICT outsourcing projects in a Malaysian environment. The mixed research method, combining the quantitative and qualitative was employed to achieve the research objectives. 110 respondents participated in a survey while focus groups from eight organizations were interviewed. From the quantitative study, the critical Information Security Risks in ICT outsourcing project were identified and ranked. Furthermore, through an exploratory factor analysis, two additional critical Information Security Risk (ISR) factors were discovered, being Information Security management defects and the challenges of managing unexpected change of service providers. Results show that organizations practiced Information Security Risk- Identification; Information Security Risk-Analysis; Information Security Risk- Treatment Plan; Information Security Risk-Treatment Plan Implementation; Information Security Risk-Monitoring; and Information Security Risk-Control. However, there was divergence in the key activities practiced due to several factors. The findings were then used as a basis for the framework development. The framework proposed step-by-step processes, activities and guidelines to be taken in managing Information Security Risk (ISR). The case study results discovered organizations had excluded some of the processes and activities due to financial, resources and time constraints. However, the framework confirmatory done through expert-judgement proves that the framework had thoroughly assessed Information Security Risk management from an outsourcing perspective and is applicable to ICT projects implemented in Malaysia. Fundamentally, the development of the framework will enable organizations to identify ISR factors and to urgently address them so that the full benefits of ICT outsourcing may be reaped.
-
Information Security Risk management: An empirical study on the importance and practices in ICT outsourcing
2010 International Symposium on Information Technology, 2010Co-Authors: Nik Zulkarnaen Khidzir, Noor Habibah Arshad, Azlinah MohamedAbstract:There are many organizations opt for outsourcing in order to cut cost and improve efficiency for their ICT services. On the other hand, ICT outsourcing could also contribute to some Risks especially Information Risks that could jeopardize Information asset in the company. An appropriate Information Security Risk management (ISRM) in ICT outsourcing should be in place in order to minimize the potential Risks and their impact to business operation as well as ICT services. The objective of this research is to conduct an empirical study on the relationship between importance and practices of ISRM in ICT Outsourcing. Questionnaires were distributed to various private companies and government agencies in Malaysia for the study. Findings of the study show that importance of ISRM process influences its practices in ICT outsourcing. Through the findings, Information Security Risk professional would be able to identify the importance of ISRM and improve their practices in managing Information Security Risk for ICT outsourcing projects. Finally, companies and government agencies need to improve their practices managing Information Risks in ICT Outsourcing.
-
Information Security Risk Management: An Empirical Study on the Difficulties and Practices in ICT Outsourcing
2010 Second International Conference on Network Applications Protocols and Services, 2010Co-Authors: Nik Zulkarnaen Khidzir, Azlinah Mohamed, Noor Habibah Hj ArshadAbstract:Information Communication Technology (ICT) services become more importance in today business environment. Most of the organizations which were not have enough resources and expertise outsource their ICT project to vendors. Conversely, the strategy could also contribute to some Risks especially Information Security Risks that could expose organizational Information assets directly involved with ICT services at Risks. An appropriate Information Security Risk management (ISRM) in ICT outsourcing should be in place to facilitate efficiency of practices how to manage Information Security Risks in ICT outsourcing. The objective of this research is to conduct an empirical study on the relationship between difficulties and practices of ISRM in ICT Outsourcing. Questionnaires were distributed to 300 private companies from various industry and government agencies in Malaysia for the study. Findings of the study show that difficulty of ISRM process influences its practices in ICT outsourcing. Through the findings, influence strength between difficulties and practices of Information Security Risk management approach in ICT outsourcing project has been discovered. Risk treatment planning task was considered as the most difficult and Risk control task was considered the least difficult in ISRM cycle. However most of the organization plans their Risk treatment task since an appropriate plan could ensure more effective Information Security Risk management implementation. In conclusion, difficulties of organization current (ISRM) practices for ICT Outsourcing shows that their current practices required for review and improvement appropriately for ICT outsourcing implementation. Hence, it's would encourage development of more comprehensible and effective approach managing Information Security Risk for ICT outsourcing project.
-
Information Security Risk factors: Critical threats vulnerabilities in ICT outsourcing
2010 International Conference on Information Retrieval & Knowledge Management (CAMP), 2010Co-Authors: Nik Zulkarnaen Khidzir, Azlinah Mohamed, Noor Habibah ArshadAbstract:Information Communication Technology (ICT) Outsourcing provides an effective ways to cut cost, launch new business venture and improve efficiency. Sometimes, ICT outsourcing can lead to an Information Security Risk incident that might be difficult to manage and mitigate. Hence, the objectives of the research are to determine the Information Security Risk factors, consisting of threats and vulnerabilities; and to discuss their criticalness in Malaysian ICT outsourcing projects. Questionnaires were distributed to various private companies and government agencies for the study. The findings of the research show that the most critical threats are system error and ICT failures; and the most critical vulnerability is insufficient attention to human factors in system design and implementation. This paper also highlights other critical Information Security Risk factors in ICT outsourcing projects. Through the findings, private companies and government agencies would be able to identify critical Information Security Risk factors and address them appropriately and effective.
Azlinah Mohamed - One of the best experts on this subject based on the ideXlab platform.
-
Information Security Risk management: An empirical study on the importance and practices in ICT outsourcing
2010 International Symposium on Information Technology, 2010Co-Authors: Nik Zulkarnaen Khidzir, Noor Habibah Arshad, Azlinah MohamedAbstract:There are many organizations opt for outsourcing in order to cut cost and improve efficiency for their ICT services. On the other hand, ICT outsourcing could also contribute to some Risks especially Information Risks that could jeopardize Information asset in the company. An appropriate Information Security Risk management (ISRM) in ICT outsourcing should be in place in order to minimize the potential Risks and their impact to business operation as well as ICT services. The objective of this research is to conduct an empirical study on the relationship between importance and practices of ISRM in ICT Outsourcing. Questionnaires were distributed to various private companies and government agencies in Malaysia for the study. Findings of the study show that importance of ISRM process influences its practices in ICT outsourcing. Through the findings, Information Security Risk professional would be able to identify the importance of ISRM and improve their practices in managing Information Security Risk for ICT outsourcing projects. Finally, companies and government agencies need to improve their practices managing Information Risks in ICT Outsourcing.
-
Information Security Risk Management: An Empirical Study on the Difficulties and Practices in ICT Outsourcing
2010 Second International Conference on Network Applications Protocols and Services, 2010Co-Authors: Nik Zulkarnaen Khidzir, Azlinah Mohamed, Noor Habibah Hj ArshadAbstract:Information Communication Technology (ICT) services become more importance in today business environment. Most of the organizations which were not have enough resources and expertise outsource their ICT project to vendors. Conversely, the strategy could also contribute to some Risks especially Information Security Risks that could expose organizational Information assets directly involved with ICT services at Risks. An appropriate Information Security Risk management (ISRM) in ICT outsourcing should be in place to facilitate efficiency of practices how to manage Information Security Risks in ICT outsourcing. The objective of this research is to conduct an empirical study on the relationship between difficulties and practices of ISRM in ICT Outsourcing. Questionnaires were distributed to 300 private companies from various industry and government agencies in Malaysia for the study. Findings of the study show that difficulty of ISRM process influences its practices in ICT outsourcing. Through the findings, influence strength between difficulties and practices of Information Security Risk management approach in ICT outsourcing project has been discovered. Risk treatment planning task was considered as the most difficult and Risk control task was considered the least difficult in ISRM cycle. However most of the organization plans their Risk treatment task since an appropriate plan could ensure more effective Information Security Risk management implementation. In conclusion, difficulties of organization current (ISRM) practices for ICT Outsourcing shows that their current practices required for review and improvement appropriately for ICT outsourcing implementation. Hence, it's would encourage development of more comprehensible and effective approach managing Information Security Risk for ICT outsourcing project.
-
Information Security Risk factors: Critical threats vulnerabilities in ICT outsourcing
2010 International Conference on Information Retrieval & Knowledge Management (CAMP), 2010Co-Authors: Nik Zulkarnaen Khidzir, Azlinah Mohamed, Noor Habibah ArshadAbstract:Information Communication Technology (ICT) Outsourcing provides an effective ways to cut cost, launch new business venture and improve efficiency. Sometimes, ICT outsourcing can lead to an Information Security Risk incident that might be difficult to manage and mitigate. Hence, the objectives of the research are to determine the Information Security Risk factors, consisting of threats and vulnerabilities; and to discuss their criticalness in Malaysian ICT outsourcing projects. Questionnaires were distributed to various private companies and government agencies for the study. The findings of the research show that the most critical threats are system error and ICT failures; and the most critical vulnerability is insufficient attention to human factors in system design and implementation. This paper also highlights other critical Information Security Risk factors in ICT outsourcing projects. Through the findings, private companies and government agencies would be able to identify critical Information Security Risk factors and address them appropriately and effective.
Tim Voss - One of the best experts on this subject based on the ideXlab platform.
-
Information Security Risk Assessment, Aggregation, and Mitigation
Information Security and Privacy, 2004Co-Authors: Arjen Lenstra, Tim VossAbstract:As part of their compliance process with the Basel 2 operational Risk management requirements, banks must define how they deal with Information Security Risk management. In this paper we describe work in progress on a new quantitative model to assess and aggregate Information Security Risks that is currently under development for deployment. We show how to find a Risk mitigation strategy that is optimal with respect to the model used and the available budget.
-
ACISP - Information Security Risk Assessment, Aggregation, and Mitigation
Information Security and Privacy, 2004Co-Authors: Arjen Lenstra, Tim VossAbstract:As part of their compliance process with the Basel 2 operational Risk management requirements, banks must define how they deal with Information Security Risk management. In this paper we describe work in progress on a new quantitative model to assess and aggregate Information Security Risks that is currently under development for deployment. We show how to find a Risk mitigation strategy that is optimal with respect to the model used and the available budget.
Noor Habibah Arshad - One of the best experts on this subject based on the ideXlab platform.
-
Information Security Risk management: An empirical study on the importance and practices in ICT outsourcing
2010 International Symposium on Information Technology, 2010Co-Authors: Nik Zulkarnaen Khidzir, Noor Habibah Arshad, Azlinah MohamedAbstract:There are many organizations opt for outsourcing in order to cut cost and improve efficiency for their ICT services. On the other hand, ICT outsourcing could also contribute to some Risks especially Information Risks that could jeopardize Information asset in the company. An appropriate Information Security Risk management (ISRM) in ICT outsourcing should be in place in order to minimize the potential Risks and their impact to business operation as well as ICT services. The objective of this research is to conduct an empirical study on the relationship between importance and practices of ISRM in ICT Outsourcing. Questionnaires were distributed to various private companies and government agencies in Malaysia for the study. Findings of the study show that importance of ISRM process influences its practices in ICT outsourcing. Through the findings, Information Security Risk professional would be able to identify the importance of ISRM and improve their practices in managing Information Security Risk for ICT outsourcing projects. Finally, companies and government agencies need to improve their practices managing Information Risks in ICT Outsourcing.
-
Information Security Risk factors: Critical threats vulnerabilities in ICT outsourcing
2010 International Conference on Information Retrieval & Knowledge Management (CAMP), 2010Co-Authors: Nik Zulkarnaen Khidzir, Azlinah Mohamed, Noor Habibah ArshadAbstract:Information Communication Technology (ICT) Outsourcing provides an effective ways to cut cost, launch new business venture and improve efficiency. Sometimes, ICT outsourcing can lead to an Information Security Risk incident that might be difficult to manage and mitigate. Hence, the objectives of the research are to determine the Information Security Risk factors, consisting of threats and vulnerabilities; and to discuss their criticalness in Malaysian ICT outsourcing projects. Questionnaires were distributed to various private companies and government agencies for the study. The findings of the research show that the most critical threats are system error and ICT failures; and the most critical vulnerability is insufficient attention to human factors in system design and implementation. This paper also highlights other critical Information Security Risk factors in ICT outsourcing projects. Through the findings, private companies and government agencies would be able to identify critical Information Security Risk factors and address them appropriately and effective.