• DocumentCode
    2387334
  • Title

    Information security risk factors: Critical threats vulnerabilities in ICT outsourcing

  • Author

    Khidzir, Nik Zulkarnaen ; Mohamed, Azlinah ; Arshad, Noor Habibah

  • Author_Institution
    Dept. of Syst. Sci. Fac. of Comput. & Math. Sci., Univ. Teknol. MARA, Shah Alam, Malaysia
  • fYear
    2010
  • fDate
    17-18 March 2010
  • Firstpage
    194
  • Lastpage
    199
  • Abstract
    Information Communication Technology (ICT) Outsourcing provides an effective ways to cut cost, launch new business venture and improve efficiency. Sometimes, ICT outsourcing can lead to an information security risk incident that might be difficult to manage and mitigate. Hence, the objectives of the research are to determine the information security risk factors, consisting of threats and vulnerabilities; and to discuss their criticalness in Malaysian ICT outsourcing projects. Questionnaires were distributed to various private companies and government agencies for the study. The findings of the research show that the most critical threats are system error and ICT failures; and the most critical vulnerability is insufficient attention to human factors in system design and implementation. This paper also highlights other critical information security risk factors in ICT outsourcing projects. Through the findings, private companies and government agencies would be able to identify critical information security risk factors and address them appropriately and effective.
  • Keywords
    business data processing; cost reduction; human factors; organisational aspects; outsourcing; risk management; security of data; ICT failures; Malaysian ICT outsourcing projects; cost cutting; critical threats; critical vulnerability; government agencies; human factors; information communication technology; information security risk factors; insufficient attention; new business venture; private companies; questionnaires; system design; system error; system implementation; Business communication; Communications technology; Costs; Data security; Government; Indium tin oxide; Information security; Knowledge transfer; Outsourcing; Risk management; Information Communication Technology; Information Security Risk Factors; Outsourcing; Threats; Vulnerabilities;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Retrieval & Knowledge Management, (CAMP), 2010 International Conference on
  • Conference_Location
    Shah Alam, Selangor
  • Print_ISBN
    978-1-4244-5650-5
  • Type

    conf

  • DOI
    10.1109/INFRKM.2010.5466918
  • Filename
    5466918