4.5 Article

Information security incident management: Current practice as reported in the literature

期刊

COMPUTERS & SECURITY
卷 45, 期 -, 页码 42-57

出版社

ELSEVIER ADVANCED TECHNOLOGY
DOI: 10.1016/j.cose.2014.05.003

关键词

Information security; Incident management; Incident response; ISO/IEC 27035; Systematic review

资金

  1. Research Council of Norway [201557]

向作者/读者索取更多资源

This paper reports results of a systematic literature review on current practice and experiences with incident management, covering a wide variety of organisations. Identified practices are summarised according to the incident management phases of ISO/IEC 27035. The study shows that current practice and experience seem to be in line with the standard. We identify some inspirational examples that will be useful for organisations looking to improve their practices, and highlight which recommended practices generally are challenging to follow. We provide suggestions for addressing the challenges, and present identified research needs within information security incident management. (C) 2014 Elsevier Ltd. All rights reserved.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.5
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据