Title :
Making Successful Security Decisions: A Qualitative Evaluation
Author :
Pettigrew, James A., III ; Ryan, Julie J C H
Abstract :
How do IT security managers make decisions in the absence of empirical data, and how do they know these decisions are successful? Some security managers seem more successful at making decisions than others. Are they guessing, or are they using some tacit knowledge? To address these questions, a study employed open-ended interviews with highly regarded, experienced security practitioners.
Keywords :
decision making; security of data; IT security managers; open-ended interviews; security decision making; security practitioners; Decision making; Educational institutions; Information security; Privacy; computer security; information security management; qualitative research; security decision-making;
Journal_Title :
Security & Privacy, IEEE
DOI :
10.1109/MSP.2011.128