Conference Proceedings
Towards a knowledge perspective in information security risk assessments - An illustrative case study
P Shedden, W Smith, R Scheepers, A Ahmad
Acis 2009 Proceedings 20th Australasian Conference on Information Systems | Published : 2009
Abstract
Many methodologies exist to assess the security risks associated with unauthorized leakage, modification and interruption of information for a given organisation. We argue that the traditional orientation of these methodologies, towards the identification and assessment of technical information assets, obscures key risks associated with the cultivation and deployment of organisational knowledge. Our argument is developed through an illustrative case study in which a well-documented methodology is applied to a complex data back-up process. This process is seen to depend, in subtle and often informal ways, on knowledge to sustain operational complexity, handle exceptions and make frequent inte..
View full abstract