The Experts below are selected from a list of 285 Experts worldwide ranked by ideXlab platform

Carl S. Young - One of the best experts on this subject based on the ideXlab platform.

  • Information Technology Risk Measurements and Metrics
    Information Security Science, 2016
    Co-Authors: Carl S. Young
    Abstract:

    This chapter describes various measurements and resulting metrics that can yield insights into the root causes of Information Technology Risk. These metrics are intended to facilitate inferences about the effectiveness of underlying Risk management processes. The relationship between internal vulnerabilities and external threat intelligence is incorporated into one measurement of Risk. Statistical correlation measurements are also used to examine trends in time series of vulnerabilities. Such measurements enable Tier ratings of high-level security controls as defined in the NIST Cybersecurity Framework.

  • Information Technology Risk Factors
    Information Security Science, 2016
    Co-Authors: Carl S. Young
    Abstract:

    This chapter discusses the principal sources of Risk factors for Information security: business practices, security governance, Information Technology implementation, user behavior, and the physical security of Information assets. The nexus between Risk-based policies and standards to security Risk metrics is also highlighted. The role of organizational culture is discussed since it can strongly affect the Risk factors for Information compromise.

  • Special Information Technology Risk Measurements and Metrics
    Information Security Science, 2016
    Co-Authors: Carl S. Young
    Abstract:

    This chapter presents a variety of specialized Information security Risk models, measurements, and metrics. Some of these are unique to Information security but others have been borrowed from other science and engineering disciplines. The use of the Markov process and Fourier analysis is particularly noteworthy given their broad usage in many other contexts. These methods are suggested here as a means of identifying Risk-relevant behaviors within large and/or complex data sets, for example, firewall logs.

Houston H. Carr - One of the best experts on this subject based on the ideXlab platform.

  • Risk analysis for Information Technology
    Journal of Management Information Systems, 1991
    Co-Authors: Rex Kelly Rainer, Charles A. Snyder, Houston H. Carr
    Abstract:

    As Information Technology (IT) has become increasingly important to the competitive position of firms, managers have grown more sensitive to their organization's overall IT Risk management. Recent publicity concerning losses incurred by companies because of problems with their sophisticated Information systems has focused attention on the importance of these systems to the organization. In an attempt to minimize or avoid such losses, managers are employing various qualitative and quantitative Risk analysis methodologies. The Risk analysis literature, however, suggests that these managers typically utilize a single methodology, not a combination of methodologies. This paper proposes a Risk analysis process that employs a combination of qualitative and quantitative methodologies. This process should provide managers with a better approximation of their organization's overall Information Technology Risk posture. Practicing managers can use this proposed process as a guideline in formulating new Risk analysis procedures and/or evaluating their current Risk analysis procedures. ABSTRACT FROM AUTHOR

Ashley A Bush - One of the best experts on this subject based on the ideXlab platform.

  • Cousins Separated by a Common Language: Perceptions of Information Technology Risk
    The International Journal of Digital Accounting Research, 2014
    Co-Authors: James L Worrell, Ashley A Bush, Paul Michael Di Gangi
    Abstract:

    The authors employ a seeded, ranking type Delphi to answer the following research question: how do each of the major stakeholder groups within organizations (representing both strategic and operational levels) conceptualize the Risks associated with IT in operations? Using three expert panels drawn from Big 4 IT audit groups and Fortune 1000 business/IT managers, we identify the IT Risks most salient to these groups, explore areas of convergence/divergence among them, and offer theoretical and practical implications from this research.

  • perceptions of Information Technology Risk a delphi study
    Americas Conference on Information Systems, 2007
    Co-Authors: James L Worrell, Ashley A Bush
    Abstract:

    Reliance on IT has complicated Risk management efforts by introducing IT Risk, defined as the Risk that an organization’s Information systems will not adequately support achieving business objectives, sufficiently safeguard Information resources, or deliver accurate and complete Information to users. There are multiple stakeholders involved in the effort to manage IT Risk, however it is not clear how these different stakeholder groups perceive this Risk. We conducted a Delphi study consisting of three expert panels from “Big 4” public accounting firms and Fortune 1000 companies to investigate perceptual differences among three key stakeholder groups: IT audit and security experts, business users of IT, and IT professionals. Our results suggest that these stakeholder groups not only lack consensus on important IT-related Risk factors within their groups but also across groups. This research highlights the importance of accounting for multiple perspectives in Risk management activities.

  • AMCIS - Perceptions of Information Technology Risk: A Delphi Study
    2007
    Co-Authors: James L Worrell, Ashley A Bush
    Abstract:

    Reliance on IT has complicated Risk management efforts by introducing IT Risk, defined as the Risk that an organization’s Information systems will not adequately support achieving business objectives, sufficiently safeguard Information resources, or deliver accurate and complete Information to users. There are multiple stakeholders involved in the effort to manage IT Risk, however it is not clear how these different stakeholder groups perceive this Risk. We conducted a Delphi study consisting of three expert panels from “Big 4” public accounting firms and Fortune 1000 companies to investigate perceptual differences among three key stakeholder groups: IT audit and security experts, business users of IT, and IT professionals. Our results suggest that these stakeholder groups not only lack consensus on important IT-related Risk factors within their groups but also across groups. This research highlights the importance of accounting for multiple perspectives in Risk management activities.

Rex Kelly Rainer - One of the best experts on this subject based on the ideXlab platform.

  • Risk analysis for Information Technology
    Journal of Management Information Systems, 1991
    Co-Authors: Rex Kelly Rainer, Charles A. Snyder, Houston H. Carr
    Abstract:

    As Information Technology (IT) has become increasingly important to the competitive position of firms, managers have grown more sensitive to their organization's overall IT Risk management. Recent publicity concerning losses incurred by companies because of problems with their sophisticated Information systems has focused attention on the importance of these systems to the organization. In an attempt to minimize or avoid such losses, managers are employing various qualitative and quantitative Risk analysis methodologies. The Risk analysis literature, however, suggests that these managers typically utilize a single methodology, not a combination of methodologies. This paper proposes a Risk analysis process that employs a combination of qualitative and quantitative methodologies. This process should provide managers with a better approximation of their organization's overall Information Technology Risk posture. Practicing managers can use this proposed process as a guideline in formulating new Risk analysis procedures and/or evaluating their current Risk analysis procedures. ABSTRACT FROM AUTHOR

James L Worrell - One of the best experts on this subject based on the ideXlab platform.

  • Cousins Separated by a Common Language: Perceptions of Information Technology Risk
    The International Journal of Digital Accounting Research, 2014
    Co-Authors: James L Worrell, Ashley A Bush, Paul Michael Di Gangi
    Abstract:

    The authors employ a seeded, ranking type Delphi to answer the following research question: how do each of the major stakeholder groups within organizations (representing both strategic and operational levels) conceptualize the Risks associated with IT in operations? Using three expert panels drawn from Big 4 IT audit groups and Fortune 1000 business/IT managers, we identify the IT Risks most salient to these groups, explore areas of convergence/divergence among them, and offer theoretical and practical implications from this research.

  • perceptions of Information Technology Risk a delphi study
    Americas Conference on Information Systems, 2007
    Co-Authors: James L Worrell, Ashley A Bush
    Abstract:

    Reliance on IT has complicated Risk management efforts by introducing IT Risk, defined as the Risk that an organization’s Information systems will not adequately support achieving business objectives, sufficiently safeguard Information resources, or deliver accurate and complete Information to users. There are multiple stakeholders involved in the effort to manage IT Risk, however it is not clear how these different stakeholder groups perceive this Risk. We conducted a Delphi study consisting of three expert panels from “Big 4” public accounting firms and Fortune 1000 companies to investigate perceptual differences among three key stakeholder groups: IT audit and security experts, business users of IT, and IT professionals. Our results suggest that these stakeholder groups not only lack consensus on important IT-related Risk factors within their groups but also across groups. This research highlights the importance of accounting for multiple perspectives in Risk management activities.

  • AMCIS - Perceptions of Information Technology Risk: A Delphi Study
    2007
    Co-Authors: James L Worrell, Ashley A Bush
    Abstract:

    Reliance on IT has complicated Risk management efforts by introducing IT Risk, defined as the Risk that an organization’s Information systems will not adequately support achieving business objectives, sufficiently safeguard Information resources, or deliver accurate and complete Information to users. There are multiple stakeholders involved in the effort to manage IT Risk, however it is not clear how these different stakeholder groups perceive this Risk. We conducted a Delphi study consisting of three expert panels from “Big 4” public accounting firms and Fortune 1000 companies to investigate perceptual differences among three key stakeholder groups: IT audit and security experts, business users of IT, and IT professionals. Our results suggest that these stakeholder groups not only lack consensus on important IT-related Risk factors within their groups but also across groups. This research highlights the importance of accounting for multiple perspectives in Risk management activities.