Managing emerging information security risks during transitions to Integrated Operations

被引:0
|
作者
Qian, Ying
Fang, Yulin
Jaatun, Martin Gilje
Johnsen, Stig Ole
Gonzalez, Jose J.
机构
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The Norwegian Oil and Gas Industry is adopting new information communication technology to connect its offshore platforms, onshore control centers and the suppliers The management of the oil companies is generally aware of the increasing risks associated with the transition, but so far, investment in incident response (IR) capability has not been highly prioritized because of uncertainty related to risks and the present reactive mental model for security risk management. In this paper, we extend previous system dynamics models on operation transition and change of vulnerability, investigating the role of IR capability in controlling the severity of incidents. The model simulation shows that a reactive approach to security risk management might trap the organization in low IR capability and lead to severe incidents With a long-term view, proactive investment in IR capability is of financial benefit.
引用
收藏
页码:2731 / 2741
页数:11
相关论文
共 50 条
  • [21] Special Issue on Managing Information Security Risks in Digital Business Guest Editorial Preface
    Luo, Xin
    Hsu, Carol
    Demetis, Dionysios
    JOURNAL OF DATABASE MANAGEMENT, 2019, 30 (03) : VII - VIII
  • [22] CAESAR8: An agile enterprise architecture approach to managing information security risks
    Loft, Paul
    He, Ying
    Yevseyeva, Iryna
    Wagner, Isabel
    COMPUTERS & SECURITY, 2022, 122
  • [23] Managing security risks for inter-organisational information systems: a multiagent collaborative model
    Feng, Nan
    Wu, Harris
    Li, Minqiang
    Wu, Desheng
    Chen, Fuzan
    Tian, Jin
    ENTERPRISE INFORMATION SYSTEMS, 2016, 10 (07) : 751 - 770
  • [24] Corporate IT Risk Management Model: a Holistic view at Managing Information System Security Risks
    Spremic, Mario
    PROCEEDINGS OF THE ITI 2012 34TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY INTERFACES (ITI), 2012, : 299 - 304
  • [25] INFORMATION RISKS AND ECONOMIC SECURITY
    Okhrimenko, S. A.
    Solonenko, O.
    FINANCIAL AND CREDIT ACTIVITY-PROBLEMS OF THEORY AND PRACTICE, 2010, 1 (08): : 200 - 204
  • [26] Information security: Coping with risks
    Malik, B
    FORBES, 1997, : 26 - &
  • [27] Managing emerging pathogen risks in recycled water
    Short, M. D.
    van den Akker, B.
    Monis, P.
    Donner, E.
    MICROBIOLOGY AUSTRALIA, 2022, 43 (04) : 177 - 182
  • [28] Information Security Risks and Managed Security Service
    Navarro, Luis
    Information Security Technical Report, 2001, 6 (03): : 28 - 36
  • [29] Perspectives of Managing Mobile Service Security Risks
    AlSudiary, Mohammed Ahmed Truki
    INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2015,
  • [30] New Frontiers: Assessing and Managing Security Risks
    Oppliger, Rolf
    Pernul, Gnther
    Katsikas, Sokratis
    COMPUTER, 2017, 50 (04) : 49 - 51