Information Security Management in SMEs: Beyond the IT Challenges
نویسندگان
چکیده
In this paper we report some results of a survey involving 33 Small and Medium-sized Enterprises (SMEs) in the UK on how they approach information security risks and what the human and organisational issues related to their risk-management practices are. All of the interviewed employees are handling sensitive data, needed to do their job, but without necessarily having the most knowledge or responsibility related to information security. The qualitative approach used was intended to be more deeply insightful and informative than others, for the purpose to understand security practices gaps, and how to improve them, as normal employees are the ones concerned with the deployment of security controls and measures in their own work practices. Our findings show that while there is a wide agreement about the importance of security and its potential impact on company performance, the understanding of security is rather taking a technology-oriented perspective. Actual work practices and routines of most employees were however ignored or not intertwined with security management efforts. Deficiencies were identified in preventive mechanisms, in incident reporting and management as well as in risk analysis process. Beyond the IT challenges, SMEs will need to have in place more efficient training and awareness programmes and organizational processes to develop more resilient security capabilities. Our conclusion is that there is a much-needed involvement of practitioners with operational knowledge in risk management and security policy definition.
منابع مشابه
Top Benefits and Hindrances to Cloud Computing Adoption in Saudi Arabia: A Brief Study
Cloud computing is an emerging concept of information technology that in many countries has an influence on many companies. The research was conducted to evaluate cloud computing adoption in Saudi Arabia; Benefits and hindrances for small and medium-sized enterprises (SMEs). The qualitative research approach is performed by interviews with the management of a variety of SMEs active in the infor...
متن کاملEnabling Information Security Culture: Influences and Challenges for Australian SMEs
An effective information security culture is vital to the success of information systems governance, risk management and compliance. Small and medium size enterprises (SMEs) face special challenges developing an information security culture as they may lack the information security knowledge, skills and behaviours of large organisations. This paper reports the main findings from an interpretive...
متن کاملInformation Technology (IT) Security Management in Kenyan Small and Medium Enterprises (SMEs)
The aim of this paper is to study the management of Information Technology (IT) security in Kenyan Small and Medium Enterprises (SMEs). Particularly, this study looks at whether SMEs have a designated employee in charge of IT security, whether SMEs seek external expertise about IT security where it is not internally available and if employees are aware that IT security incidents should be repor...
متن کاملManaging Information Security in Small and Medium Sized Enterprises: A Holistic Approach
Small to medium sized enterprises (SMEs) constitute a major part of the global economic activity. Due to the distinct characteristics of these enterprises, approaches to information security management that were mainly developed for larger organisations can not be feasibly applied in the context of SMEs. In this paper, we present some of the challenges impeding the implementation of information...
متن کاملPROVIDE A MODEL FOR IDENTIFYING AND RANKING THE MANAGERIAL FACTORS AFFECTING INFORMATION SECURITY IN ORGANIZATION BY USING VIKOR METHOD; CASE STUDY: TEHRAN UNIVERSITY OF MEDICAL SCIENCES
<span style="color: #000000; font-family: Tahoma, sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: -webkit-left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; display: inline !important; float: none; ba...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2016