Conceptualizing the Domain and an Empirical Analysis of Operations Security Management

Research output: Chapter in Book/Report/Conference proceedingChapterpeer-review

Abstract

Operations security management integrates the activities of all the information systems security controls. It ensures that the entire computing environment is adequately secured. This chapter conducts an in-depth review of scholarly and practitioner works to conceptualize the domain of operations security management. Drawing upon the existing information systems security literature, the chapter classifies operations security management into 10 domains. Following, the chapter performs an empirical analysis to investigate the state-of-practice of operations security management in organizations. The findings show that the maturity level of operations security management is at the Level 3 (well-defined). The maturity levels range from Level 0 (not performed) to Level 5 (continuously improving). The results indicate that operations security processes are documented, approved, and implemented organization-wide. Backup and malware management are the most applied operations security controls, while logging, auditing, monitoring, and reviewing are the least implemented controls.

Original languageEnglish
Title of host publicationResearch Anthology on Business Aspects of Cybersecurity
PublisherIGI Global
Pages533-560
Number of pages28
ISBN (Electronic)9781668436998
ISBN (Print)9781668436981
DOIs
Publication statusPublished - 1 Jan 2021
Externally publishedYes

Fingerprint

Dive into the research topics of 'Conceptualizing the Domain and an Empirical Analysis of Operations Security Management'. Together they form a unique fingerprint.

Cite this