The Experts below are selected from a list of 15 Experts worldwide ranked by ideXlab platform
Atif Ahmad - One of the best experts on this subject based on the ideXlab platform.
-
information Security Risk assessment towards a business practice perspective
Australian Information Security Management Conference, 2010Co-Authors: Piya Shedden, Wally Smith, Atif AhmadAbstract:Information Security Risk assessments (ISRAs) are of great importance for organisations. Current ISRA methods identify an organisation’s Security Risks and provide a measured, analysed Security Risk Profile of critical information assets in order to build plans to treat Risk. However, despite prevalent use in organisations today, current methods adopt a limited view of information assets during Risk identification. In the context of day-to-day activities, people copy, print and discuss information, leading to the ‘leakage’ of information assets. Employees will create and use unofficial assets as part of their day-to-day routines. Furthermore, employees will also possess important knowledge on how to perform their functions within a business process or information system. These are all elements of business ‘practice’, a perspective that would yield a richer and holistic understanding of an organisation’s information assets and vulnerabilities. This perspective is not captured by traditional ISRA methods, leading to an incomplete view of an organisation’s information systems and processes that could prove detrimental and damaging. This paper hence suggests that a business practice perspective be incorporated into ISRA methods in order to identify information leakage, unofficial, critical information assets and critical process knowledge of organisations.
-
exploring the relationship between organizational culture and information Security culture
Australian Information Security Management Conference, 2009Co-Authors: Joo Soon Lim, Shanton Chang, Sean B Maynard, Atif AhmadAbstract:Managing Information Security is becoming more challenging in today's business because people are both a cause of information Security incidents as well as a key part of the protection from them. As the impact of organizational culture (OC) on employees is significant, many researchers have called for the creation of information Security culture (ISC) in organizations to influence the actions and behaviour of employees towards better organizational information Security. Although researchers have called for the creation of ISC to be embedded in organizations, nonetheless, literature suggests that little past research examining the relationship between the nature of OC and ISC. This paper seeks to explore the relationship between the nature of OC and ISC and argues that organizations that have a medium to high Security Risk Profile need to embed the ISC to influence employee actions and behaviours in relation to information Security practices. In addition, this paper also introduces a framework to assist organizations in determining the extent to which the desired ISC is embedded into OC. © 2009 Lim, Chang, Maynard & Ahmad.
Joo Soon Lim - One of the best experts on this subject based on the ideXlab platform.
-
exploring the relationship between organizational culture and information Security culture
Australian Information Security Management Conference, 2009Co-Authors: Joo Soon Lim, Shanton Chang, Sean B Maynard, Atif AhmadAbstract:Managing Information Security is becoming more challenging in today's business because people are both a cause of information Security incidents as well as a key part of the protection from them. As the impact of organizational culture (OC) on employees is significant, many researchers have called for the creation of information Security culture (ISC) in organizations to influence the actions and behaviour of employees towards better organizational information Security. Although researchers have called for the creation of ISC to be embedded in organizations, nonetheless, literature suggests that little past research examining the relationship between the nature of OC and ISC. This paper seeks to explore the relationship between the nature of OC and ISC and argues that organizations that have a medium to high Security Risk Profile need to embed the ISC to influence employee actions and behaviours in relation to information Security practices. In addition, this paper also introduces a framework to assist organizations in determining the extent to which the desired ISC is embedded into OC. © 2009 Lim, Chang, Maynard & Ahmad.
Shanton Chang - One of the best experts on this subject based on the ideXlab platform.
-
exploring the relationship between organizational culture and information Security culture
Australian Information Security Management Conference, 2009Co-Authors: Joo Soon Lim, Shanton Chang, Sean B Maynard, Atif AhmadAbstract:Managing Information Security is becoming more challenging in today's business because people are both a cause of information Security incidents as well as a key part of the protection from them. As the impact of organizational culture (OC) on employees is significant, many researchers have called for the creation of information Security culture (ISC) in organizations to influence the actions and behaviour of employees towards better organizational information Security. Although researchers have called for the creation of ISC to be embedded in organizations, nonetheless, literature suggests that little past research examining the relationship between the nature of OC and ISC. This paper seeks to explore the relationship between the nature of OC and ISC and argues that organizations that have a medium to high Security Risk Profile need to embed the ISC to influence employee actions and behaviours in relation to information Security practices. In addition, this paper also introduces a framework to assist organizations in determining the extent to which the desired ISC is embedded into OC. © 2009 Lim, Chang, Maynard & Ahmad.
Sean B Maynard - One of the best experts on this subject based on the ideXlab platform.
-
exploring the relationship between organizational culture and information Security culture
Australian Information Security Management Conference, 2009Co-Authors: Joo Soon Lim, Shanton Chang, Sean B Maynard, Atif AhmadAbstract:Managing Information Security is becoming more challenging in today's business because people are both a cause of information Security incidents as well as a key part of the protection from them. As the impact of organizational culture (OC) on employees is significant, many researchers have called for the creation of information Security culture (ISC) in organizations to influence the actions and behaviour of employees towards better organizational information Security. Although researchers have called for the creation of ISC to be embedded in organizations, nonetheless, literature suggests that little past research examining the relationship between the nature of OC and ISC. This paper seeks to explore the relationship between the nature of OC and ISC and argues that organizations that have a medium to high Security Risk Profile need to embed the ISC to influence employee actions and behaviours in relation to information Security practices. In addition, this paper also introduces a framework to assist organizations in determining the extent to which the desired ISC is embedded into OC. © 2009 Lim, Chang, Maynard & Ahmad.
Piya Shedden - One of the best experts on this subject based on the ideXlab platform.
-
information Security Risk assessment towards a business practice perspective
Australian Information Security Management Conference, 2010Co-Authors: Piya Shedden, Wally Smith, Atif AhmadAbstract:Information Security Risk assessments (ISRAs) are of great importance for organisations. Current ISRA methods identify an organisation’s Security Risks and provide a measured, analysed Security Risk Profile of critical information assets in order to build plans to treat Risk. However, despite prevalent use in organisations today, current methods adopt a limited view of information assets during Risk identification. In the context of day-to-day activities, people copy, print and discuss information, leading to the ‘leakage’ of information assets. Employees will create and use unofficial assets as part of their day-to-day routines. Furthermore, employees will also possess important knowledge on how to perform their functions within a business process or information system. These are all elements of business ‘practice’, a perspective that would yield a richer and holistic understanding of an organisation’s information assets and vulnerabilities. This perspective is not captured by traditional ISRA methods, leading to an incomplete view of an organisation’s information systems and processes that could prove detrimental and damaging. This paper hence suggests that a business practice perspective be incorporated into ISRA methods in order to identify information leakage, unofficial, critical information assets and critical process knowledge of organisations.