A Framework for Managing Security Risks of Outsourced IT Projects: An Empirical Study

被引:3
|
作者
Almutairi, Moneef [1 ]
Riddle, Stephen [1 ]
机构
[1] Newcastle Univ, Sch Comp Sci, Newcastle Upon Tyne, Tyne & Wear, England
关键词
Security Management; IT project framework; empirical study;
D O I
10.1145/3178461.3178476
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Several firms outsource their IT services partially or totally due to different constraints such as business, financial or legal. Although IT outsourcing has tremendous benefits such as cost reduction, it might expose firms to different security risks including confidentiality, integrity, and availability issues. In this paper, we present the evaluation results for a proposed framework that we developed previously for managing the security and compliance risks of outsourced IT projects. The evaluation is designed to assess several features of the proposed framework. Usefulness, flexibility, simplicity and ease of use as well as achieving a systematic and comprehensive methodology for managing the security and compliance risks of outsourced IT projects are evaluated in this paper. Additionally, we evaluate the usefulness of utilizing project phases and the proposed threat classification approach for identifying and managing security threats in the outsourcing context. Finally, we evaluate the ability of the proposed framework to be applied to any project regardless of project size, cost, or any other constraints.
引用
收藏
页码:40 / 44
页数:5
相关论文
共 50 条
  • [11] Managing Requirements Risks in IT Projects
    Mathiassen, Lars
    Tuunanen, Tuure
    IT PROFESSIONAL, 2011, 13 (06) : 40 - 46
  • [12] Managing Risks in Complex Projects
    Thamhain, Hans
    PROJECT MANAGEMENT JOURNAL, 2013, 44 (02) : 20 - 35
  • [13] Assessing the Risks of Asian Development Projects: A Theoretical Framework and Empirical Findings
    Lee, Jeongseok
    Lee, Yoonsun
    Kim, Jaejun
    JOURNAL OF ASIAN ARCHITECTURE AND BUILDING ENGINEERING, 2013, 12 (01) : 25 - 32
  • [14] Managing Outsourced Logistics Service Projects as Complex Networked Resources
    Awaleh, F.
    Engelseth, P.
    2018 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL ENGINEERING AND ENGINEERING MANAGEMENT (IEEE IEEM), 2018, : 1583 - 1587
  • [15] Managing security risks with 80001
    Mankovich, Nick
    Fitzgerald, Brian
    Biomedical Instrumentation and Technology, 2011, 45 (FALL): : 27 - 32
  • [16] Managing software security risks
    McGraw, G
    COMPUTER, 2002, 35 (04) : 99 - 101
  • [17] Agile requirements prioritization in large-scale outsourced system projects: An empirical study
    Daneva, Maya
    van der Veen, Egbert
    Amrit, Chintan
    Ghaisas, Smita
    Sikkel, Klaas
    Kumar, Ramesh
    Ajmeri, Nirav
    Ramteerthkar, Uday
    Wieringa, Roel
    JOURNAL OF SYSTEMS AND SOFTWARE, 2013, 86 (05) : 1333 - 1353
  • [18] Managing risks in IT projects: an options perspective
    Kumar, RL
    INFORMATION & MANAGEMENT, 2002, 40 (01) : 63 - 74
  • [19] Managing execution risks for LNG projects
    Mokhatab, Saeid
    HYDROCARBON PROCESSING, 2007, 86 (10): : 17 - 17
  • [20] Managing the risks of offshore IT development projects
    Kliem, R
    INFORMATION SYSTEMS MANAGEMENT, 2004, 21 (03) : 22 - 27