Mid Sweden University

miun.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Information Technology Consulting Firms’ Readiness for Managing Information Security Incidents
Mid Sweden University, Faculty of Science, Technology and Media, Department of Information Systems and Technology. (RCR, FODI)ORCID iD: 0000-0003-4869-5094
(FODI)
Mid Sweden University, Faculty of Science, Technology and Media, Department of Information Systems and Technology. (FODI)ORCID iD: 0000-0002-1337-0479
2020 (English)In: Information Systems Security and Privacy / [ed] Paolo Mori, Steven Furnell, Olivier Camp, Springer Publishing Company, 2020, p. 48-73Chapter in book (Refereed)
Abstract [en]

Because of the increase in the number and scope of information security incidents, proper management has recently gained importance for public and private organizations. Further challenges in this area have resulted from new regulations, such as the General Data Protection Regulation (GDPR) and the Directive on Security of Network and Information Systems (NIS), as well as a tendency to outsource vital services to subcontractors. This study addresses the lack of empirical studies in the field and focuses on information security incident management at information technology (IT) consulting firms.Specifically, it examines challenges due to their exposed position and newregulations. The contribution of the paper is twofold. First, it provides valuable insight into the experiences and challenges of Swedish IT consulting firms.Second, it proposes criteria for classifying an information security incident that can equip decision-makers with a solid and assessable basis for incident management. The results emphasize further improvements in employee awareness, incident classification, and systemic governance, thereby integrating corporate policy making, information security incident management, and information system leadership.

Place, publisher, year, edition, pages
Springer Publishing Company, 2020. p. 48-73
Series
Communications in Computer and Information Science
Keywords [en]
Security awareness, Information security incident management, Systemic governance, Incident classification, GDPR, NIS directive
National Category
Computer and Information Sciences Information Systems
Identifiers
URN: urn:nbn:se:miun:diva-39390DOI: 10.1007/978-3-030-49443-8_3Scopus ID: 2-s2.0-85088245303ISBN: 978-3-030-49442-1 (print)ISBN: 978-3-030-49443-8 (electronic)OAI: oai:DiVA.org:miun-39390DiVA, id: diva2:1449529
Available from: 2020-06-30 Created: 2020-06-30 Last updated: 2020-08-18Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full textScopusSpringer book

Authority records

Große, ChristineSundberg, Leif

Search in DiVA

By author/editor
Große, ChristineNyman, MajaSundberg, Leif
By organisation
Department of Information Systems and Technology
Computer and Information SciencesInformation Systems

Search outside of DiVA

GoogleGoogle Scholar

doi
isbn
urn-nbn

Altmetric score

doi
isbn
urn-nbn
Total: 118 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf