论文标题

信息安全方面的风险管理实践:探索DACH地区的现状

Risk Management Practices in Information Security: Exploring the Status Quo in the DACH Region

论文作者

Brunner, Michael, Sauerwein, Clemens, Felderer, Michael, Breu, Ruth

论文摘要

信息安全管理旨在确保对信息价值和信息处理系统(即资产)的正确保护。信息安全风险管理技术纳入了处理威胁和脆弱性,这些威胁和漏洞将这些资产的信息安全性属性施加风险。本文调查了当前在DACH地区(德国,奥地利,瑞士)的信息安全管理中使用的风险管理状况。我们使用了针对战略和操作信息安全和风险管理者的匿名在线调查,并从26个组织收集了数据。我们分析了一般实践,文档工件,利益相关者协作的模式以及企业用于开展信息安全管理活动的工具类型和数据源。我们的发现表明,信息安全风险管理的实践状态需要改进。当前的工业实践在很大程度上依赖于手动数据收集和复杂的潜在主观决策过程,其中包括多个利益相关者。选择性地使用专用风险管理工具和方法,并忽略了有利于通用文档工具和利益相关者之间的直接通信。鉴于我们的结果,我们提出了针对风险管理实践的开发指南,这些指南与信息安全管理中当前的运营状况更好地保持一致。

Information security management aims at ensuring proper protection of information values and information processing systems (i.e. assets). Information security risk management techniques are incorporated to deal with threats and vulnerabilities that impose risks to information security properties of these assets. This paper investigates the current state of risk management practices being used in information security management in the DACH region (Germany, Austria, Switzerland). We used an anonymous online survey targeting strategic and operative information security and risk managers and collected data from 26 organizations. We analyzed general practices, documentation artifacts, patterns of stakeholder collaboration as well as tool types and data sources used by enterprises to conduct information security management activities. Our findings show that the state of practice of information security risk management is in need of improvement. Current industrial practice heavily relies on manual data collection and complex potentially subjective decision processes with multiple stakeholders involved. Dedicated risk management tools and methods are used selectively and neglected in favor of general-purpose documentation tools and direct communication between stakeholders. In light of our results we propose guidelines for the development of risk management practices that are better aligned with the current operational situation in information security management.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源