Managing information security risks during new technology adoption

被引:12
|
作者
Qian, Ying [2 ]
Fang, Yulin [1 ]
Gonzalez, Jose J. [3 ]
机构
[1] City Univ Hong Kong, Dept Informat Syst, Hong Kong, Hong Kong, Peoples R China
[2] Shanghai Univ, Sch Management, Shanghai 200041, Peoples R China
[3] Univ Agder, Fac Sci & Engn, Agder, Norway
基金
中国国家自然科学基金;
关键词
Information security management; System dynamics; Integrated Operations; Delay; Proactive investment; Reactive investment;
D O I
10.1016/j.cose.2012.09.001
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the present study, we draw on previous system dynamics research on operational transition and change of vulnerability to investigate the role of incident response capability in controlling the severity of incidents during the adoption of new technology. Toward this end, we build a system dynamics model using the Norwegian Oil and Gas Industry as the context. The Norwegian Oil and Gas Industry has started to adopt new information communication technology to connect its offshore platforms, onshore control centers, and suppliers. In oil companies, the management is generally aware of the increasing risks associated with operational transition; however, to date, investment in incident response capability has not been highly prioritized because of the uncertainty related to risks and the present reactive mental model of security risk management. The model simulation shows that a reactive approach to security risk management might trap the organization into blindness to minor incidents and low incident response capability, which can lead to severe incidents. The system dynamics model can serve as a means to promote proactive investment in incident response capability. (C) 2012 Elsevier Ltd. All rights reserved.
引用
收藏
页码:859 / 869
页数:11
相关论文
共 50 条
  • [1] Managing emerging information security risks during transitions to Integrated Operations
    Qian, Ying
    Fang, Yulin
    Jaatun, Martin Gilje
    Johnsen, Stig Ole
    Gonzalez, Jose J.
    43RD HAWAII INTERNATIONAL CONFERENCE ON SYSTEMS SCIENCES VOLS 1-5 (HICSS 2010), 2010, : 2731 - 2741
  • [2] Managing Information Technology Security Risk
    Gilliam, DP
    SOFTWARE SECURITY - THEORIES AND SYSTEMS, 2004, 3233 : 296 - 317
  • [3] Managing the risks of commercializing new technology
    Fisher, DE
    EMS - 2000: PROCEEDINGS OF THE 2000 IEEE ENGINEERING MANAGEMENT SOCIETY, 2000, : 512 - 518
  • [4] New Frontiers: Assessing and Managing Security Risks
    Oppliger, Rolf
    Pernul, Gnther
    Katsikas, Sokratis
    COMPUTER, 2017, 50 (04) : 49 - 51
  • [5] Information and Communication Technology for Managing Supply Chain Risks
    Tang, Christopher S.
    Zimmerman, Joshua
    COMMUNICATIONS OF THE ACM, 2013, 56 (07) : 27 - 29
  • [6] Managing Security Risks
    Abrahamson, Donald W.
    Sepeda, Adrian L.
    CHEMICAL ENGINEERING PROGRESS, 2009, 105 (07) : 41 - 47
  • [7] THE ACQUISITION OF INFORMATION AND THE ADOPTION OF NEW TECHNOLOGY
    FEDER, G
    SLADE, R
    AMERICAN JOURNAL OF AGRICULTURAL ECONOMICS, 1984, 66 (03) : 312 - 320
  • [8] INFORMATION ACQUISITION AND THE ADOPTION OF NEW TECHNOLOGY
    MCCARDLE, KF
    MANAGEMENT SCIENCE, 1985, 31 (11) : 1372 - 1389
  • [9] Role of Information Technology in Structuring and Managing Risks In The Advanced States
    Obaid, Ahmed J.
    Abdulbaqi, Azmi Shawkat
    hilmi, Shams Amer Najy
    AL-Ameedee, Sarah A.
    INTERNATIONAL JOURNAL OF EARLY CHILDHOOD SPECIAL EDUCATION, 2022, 14 (03) : 567 - 573
  • [10] Managing Climatic Risks for Enhanced Food Security: Key Information Capabilities
    Balaghi, R.
    Badjeck, M-C
    Bakari, D.
    De Pauw, E.
    De Wit, A.
    Defourny, P.
    Donato, S.
    Gommes, R.
    Jlibene, M.
    Ravelo, A. C.
    Sivakumar, M. V. K.
    Telahigue, N.
    Tychon, B.
    WORLD CLIMATE CONFERENCE - 3, 2010, 1 : 313 - 323