DocumentCode :
2387334
Title :
Information security risk factors: Critical threats vulnerabilities in ICT outsourcing
Author :
Khidzir, Nik Zulkarnaen ; Mohamed, Azlinah ; Arshad, Noor Habibah
Author_Institution :
Dept. of Syst. Sci. Fac. of Comput. & Math. Sci., Univ. Teknol. MARA, Shah Alam, Malaysia
fYear :
2010
fDate :
17-18 March 2010
Firstpage :
194
Lastpage :
199
Abstract :
Information Communication Technology (ICT) Outsourcing provides an effective ways to cut cost, launch new business venture and improve efficiency. Sometimes, ICT outsourcing can lead to an information security risk incident that might be difficult to manage and mitigate. Hence, the objectives of the research are to determine the information security risk factors, consisting of threats and vulnerabilities; and to discuss their criticalness in Malaysian ICT outsourcing projects. Questionnaires were distributed to various private companies and government agencies for the study. The findings of the research show that the most critical threats are system error and ICT failures; and the most critical vulnerability is insufficient attention to human factors in system design and implementation. This paper also highlights other critical information security risk factors in ICT outsourcing projects. Through the findings, private companies and government agencies would be able to identify critical information security risk factors and address them appropriately and effective.
Keywords :
business data processing; cost reduction; human factors; organisational aspects; outsourcing; risk management; security of data; ICT failures; Malaysian ICT outsourcing projects; cost cutting; critical threats; critical vulnerability; government agencies; human factors; information communication technology; information security risk factors; insufficient attention; new business venture; private companies; questionnaires; system design; system error; system implementation; Business communication; Communications technology; Costs; Data security; Government; Indium tin oxide; Information security; Knowledge transfer; Outsourcing; Risk management; Information Communication Technology; Information Security Risk Factors; Outsourcing; Threats; Vulnerabilities;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Retrieval & Knowledge Management, (CAMP), 2010 International Conference on
Conference_Location :
Shah Alam, Selangor
Print_ISBN :
978-1-4244-5650-5
Type :
conf
DOI :
10.1109/INFRKM.2010.5466918
Filename :
5466918
Link To Document :
بازگشت