Incentives and Perceptions of Information Security Risks Incitations et Perceptions des Risques pour la Sécurité de l'Information
نویسندگان
چکیده
Technologies and procedures for effectively securing cyberspace exist, but are largely underdeployed. One reason for this is that organizational reward systems lack the proper incentives for decision-maker allocation of resources. We identify characteristics of differing stakeholder perceptions of security and privacy risks and integrate them in a decision making framework. We significantly revise the Fischhoff and Slovic model of risk perceptions --introducing ordinal scales to the identified characteristics of risk perceptions, and incorporating the dynamics of perception by including the important and neglected time element. Over twelve months, we reviewed and verified the model with thirty five senior information security executives from industrial and governmental organizations. We present a methodology for identification of perverse incentives---situations where the interests of a manager or employee are not aligned with those of the organization; and how the policies and reward system may be modified to correct the mis-alignment.
منابع مشابه
Ontologies et raisonnement à partir de cas : Application à l'analyse des risques industriels
L’analyse de risques est un processus visant à décrire les scénarios conduisant à des phénomènes dangereux et à des accidents potentiels sur une installation industrielle. Pour réaliser une analyse de risques, un expert dispose de nombreuses ressources : rapports, études de dangers, bases d’accidents, etc. Ces ressources sont cependant souvent difficiles à exploiter parce qu’elles ne sont pas s...
متن کاملDéfis de la sécurité de l'information. Support à la gestion des risques de sécurité par les modèles
Within the organisations, information system security is more and more tackled with the help of risk management approaches. However these approaches are on one hand not well suited to be applied on information system development and on the other hand, products coming from the different risk management steps performed are generally not enough formal. Our research work proposes to improve the dif...
متن کاملThe Use of Quantitative Risk Analysis for Prioritizing Flood Risk Management Actions in the Netherlands
Almost two-thirds of the Netherlands is exposed to the risk of flooding, making the provision of flood safety a vital yet costly affair. To be able to make better informed decisions about flood risk management, the Dutch Ministry of Infrastructure and the Environment, the Association of Regional Water Authorities and the Association of Provincial Authorities commissioned a study to gain insight...
متن کاملA Theory of Environmental Risk Disclosure
Ce document est publié dans l'intention de rendre accessibles les résultats préliminaires de la recherche effectuée au CIRANO, afin de susciter des échanges et des suggestions. Les idées et les opinions émises sont sous l'unique responsabilité des auteurs, et ne représentent pas nécessairement les positions du CIRANO ou de ses partenaires. This paper presents preliminary research carried out at...
متن کاملEvolution du système national d’information sanitaire de la république démocratique du Congo entre 2009 et 2015
Résumé Introduction: Lancé en 1987, le Système national d'information sanitaire (SNIS) de la République Démocratique du Congo (DR Congo) a été évalué en 2009 et 2015 moyennant l'outil HMN (Health metrics network). L'objectif de cette étude était d'estimer les progrès réalisés entre ces deux évaluations. Méthodes: Il s'agissait d'une analyse des données secondaires des évaluations du SNIS, qui a...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2009