Back to Search Start Over

IT Risk Management: Towards a System for Enhancing Objectivity in Asset Valuation That Engenders a Security Culture.

Authors :
Metin, Bilgin
Duran, Sefa
Telli, Eda
Mutlutürk, Meltem
Wynn, Martin
Source :
Information (2078-2489); Jan2024, Vol. 15 Issue 1, p55, 27p
Publication Year :
2024

Abstract

In today's technology-centric business environment, where organizations encounter numerous cyber threats, effective IT risk management is crucial. An objective risk assessment—based on information relating to business requirements, human elements, and the security culture within an organisation—can provide a sound basis for informed decision making, effective risk prioritisation, and the implementation of suitable security measures. This paper focuses on asset valuation, supply chain risk, and enhanced objectivity—via a "segregation of duties" approach—to extend and apply the capabilities of an established security culture framework. The resultant system design aims at mitigating subjectivity in IT risk assessments, thereby diminishing personal biases and presumptions to provide a more transparent and accurate understanding of the real risks involved. Survey responses from 16 practitioners working in the private and public sectors confirmed the validity of the approach but suggest it may be more workable in larger organisations where resources allow dedicated risk professionals to operate. This research contributes to the literature on IT and cyber risk management and provides new perspectives on the need to improve objectivity in asset valuation and risk assessment. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
20782489
Volume :
15
Issue :
1
Database :
Complementary Index
Journal :
Information (2078-2489)
Publication Type :
Academic Journal
Accession number :
175078484
Full Text :
https://doi.org/10.3390/info15010055