DocumentCode :
3584955
Title :
A proposed taxonomy of assets for information security risk assessment (ISRA)
Author :
Shamala, Palaniappan ; Ahmad, Rabiah
Author_Institution :
Center for Adv. Comput. Technol., Univ. Tech. Malaysia Melaka (UTeM), Melaka, Malaysia
fYear :
2014
Firstpage :
29
Lastpage :
33
Abstract :
Information security has become a vital entity because organizations across the globe conduct business in an interconnected and information rich environment. Hence, organizations wanting to eliminate the possible risks in their organizations by conducting information security risk assessment (ISRA). By means of this ISRA, organizations are able to identify and prioritize information assets and ensure that effective control mechanisms are utilized for high-priority information assets. However, current ISRA methods have critical limitations in that they adopt merely a technical perspective. Currently available ISRA methods function in a limited view of information assets. The aim of this paper is to propose a taxonomy of assets for ISRA. The presented taxonomy of assets is not only able to guide ISRA practitioners to examine which assets are most important to the organization in the early process of doing risk assessment but also enables them to collect all the needed information associated with assets before and during their actual ISRA implementation. A structured approach was carried out using Webster & Watson guidelines for determining the source material for the review. The result shows the limitation on identifying information assets issue which have been discussed separately by various researchers but none of the researchers have combines all the human related non-technical perspective assets together under on frame as the taxonomy of assets for ISRA.
Keywords :
asset management; organisational aspects; risk management; security of data; ISRA methods; Webster-and-Watson guidelines; asset taxonomy; control mechanisms; critical limitations; high-priority information assets; human related nontechnical perspective assets; information asset identification; information asset prioritization; information security risk assessment; risk elimination; source material; technical perspective; Information security; Organizations; Risk management; Taxonomy; assets; information security risk assessment; non-technical; taxonomy; technical;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information and Communication Technologies (WICT), 2014 Fourth World Congress on
Print_ISBN :
978-1-4799-8114-4
Type :
conf
DOI :
10.1109/WICT.2014.7077297
Filename :
7077297
Link To Document :
بازگشت