"Why Wasn't I Notified?": Information Security Incident Reporting Demystified
نویسنده
چکیده
An information security incident, if successfully discovered and reported, initiates a distributed response process that activates a diverse collection of independent actors. Public officials, network service providers, information security companies, research organisations, and volunteers from all over the world can be involved; often without the participants realising whom they are working with. The cooperation is based on mostly informal bilateral arrangements and is aided by mutual trust accumulated over course of time. Each participant wants to limit their involvement and typically only assumes responsibility on their own actions. Information suggesting that third parties would be affected may or may not be followed up. The result is an unplanned mesh of bilateral information sharing and a formation of an ad-hoc network of partial stakeholders. No single entity exercises total control over the process, which makes it inherently uncontrollable and its results difficult to anticipate. This contrasts with the information security standards, where the process is expected to be well defined and under the control of a clearly stated leadership. The study suggests that internet-connected organisations should adopt a rather agnostic approach to information security incident reporting.
منابع مشابه
Security Incident Recognition and Reporting (SIRR): An Industrial Perspective
Reports and press releases highlight that security incidents continue to plague organizations. While researchers and practitioners’ alike endeavor to identify and implement realistic security solutions to prevent incidents from occurring, the ability to initially identify a security incident is paramount when researching a security incident lifecycle. Hence, this research investigates the abili...
متن کاملInvestigation of Incident Reporting System in Iranian Hospitals: A National Survey
Background and Aims: Incident reporting is a possible alternative for learning from errors. One of the barriers in this way is a deficit in, common standards for collecting, interpreting, and presenting data. In this research accordance with Iranchr('39')s incident reporting system with minimal information Model for Patient Safety Incident Reporting Systems (MIMPS)of WHO were compared. Methods:...
متن کاملAlphaCo: A Teaching Case on Information Technology Audit and Security
Recent regulations in the United States (U.S.) such as the Sarbanes-Oxley Act of 2002 require top management of a public firm to provide reasonable assurance that they institute internal controls that minimize risks over the firm’s operations and financial reporting. External auditors are required to attest to the management’s assertions over the effectiveness of those internal controls. As fir...
متن کاملCharacterizing Incidents Reporting Systems across Applications Domains
Incident reporting is a very well-known technique in application domains such as air traffic management and health, where specialized users are trained to provide detailed information about problems. Incident reporting systems are indeed complex systems that include many actors including the users reporting incidents, user’s colleagues and neighbors, stakeholders, policymakers, systems integrat...
متن کاملAttitudes toward the large-scale implementation of an incident reporting system.
OBJECTIVE An electronic Incident Information Management System implemented system-wide by the Department of Health, New South Wales, Australia was evaluated. We hypothesized that health professionals (i) would support the system via utilization and favourable attitudes and (ii) that their usage and attitudes would vary according to profession with nurses being most, and doctors least, favourabl...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2010