论文标题

影响组织决定外包安全性安全的因素:审查和研究议程

Factors Influencing the Organizational Decision to Outsource IT Security: A Review and Research Agenda

论文作者

Arshad, Antra, Ahmad, Atif, Maynard, Sean

论文摘要

IT安全外包是签约第三方安全服务提供商,即组织的全部或部分IT安全功能。关于影响组织决策在外包这样的关键功能时的因素知之甚少。我们对研究和实践文献的回顾确定了几个管理因素和法律因素。我们发现IT安全外包的研究不成熟,而重点领域没有解决行业实践面临的关键问题。因此,我们提出了一个研究议程,该研究议程包括15个问题,以解决与IT安全外包知识有关的五个关键差距,特别是对结果的有效性,实践的生活经验,时间维度,多利益相关者的观点以及对IT安全实践的影响,尤其是在事件响应中的敏捷性。

IT security outsourcing is the process of contracting a third-party security service provider to perform, the full or partial IT security functions of an organization. Little is known about the factors influencing organizational decisions in outsourcing such a critical function. Our review of the research and practice literature identified several managerial factors and legal factors. We found research in IT security outsourcing to be immature and the focus areas not addressing the critical issues facing industry practice. We therefore present a research agenda consisting of fifteen questions to address five key gaps relating to knowledge of IT security outsourcing, specifically effectiveness of the outcome, lived experience of the practice, the temporal dimension, multi-stakeholder perspectives, and the impact on IT security practices, particularly agility in incident response.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源