Abstract
Information security strategies employ principles and practices grounded in both the prevention and response paradigms. The prevention paradigm aims at managing predicted threats. Although the prevention paradigm may dominate in contemporary commercial organizations, the response paradigm (aimed at managing unpredicted threats) retains an important role in protecting information security in today's dynamic threat environment. This study provides an overarching security framework that focuses on managing the proper balance between prevention and response paradigms. We conduct a comparative case study with three European organizations. This study analyzes and empirically confirms how and why organizations balance between their prevention and response strategies.
| Original language | English |
|---|---|
| Pages (from-to) | 138-151 |
| Number of pages | 14 |
| Journal | Information and Management |
| Volume | 51 |
| Issue number | 1 |
| DOIs | |
| State | Published - Jan 2014 |
ASJC Scopus Subject Areas
- Management Information Systems
- Information Systems
- Information Systems and Management
Keywords
- Case study
- Incident-centered analysis
- Information security management
- Prevention paradigm
- Response paradigm
- Security balance
Fingerprint
Dive into the research topics of 'Incident-centered information security: Managing a strategic balance between prevention and response'. Together they form a unique fingerprint.Cite this
- APA
- Standard
- Harvard
- Vancouver
- Author
- BIBTEX
- RIS