Managing Security Objectives for Effective Organizational Performance Information Security Management

Information is a significant asset to organizations, and a data breach from a cyberattack harms reputations and may result in a massive financial loss. Many senior managers lack the competencies to implement an enterprise risk management system and align organizational resources such as people, proc...

Full description

Bibliographic Details
Main Author: Gutta, Ramamohan
Format: Others
Language:en
Published: ScholarWorks 2019
Subjects:
Online Access:https://scholarworks.waldenu.edu/dissertations/7147
https://scholarworks.waldenu.edu/cgi/viewcontent.cgi?article=8426&context=dissertations
id ndltd-waldenu.edu-oai-scholarworks.waldenu.edu-dissertations-8426
record_format oai_dc
spelling ndltd-waldenu.edu-oai-scholarworks.waldenu.edu-dissertations-84262019-10-30T01:22:42Z Managing Security Objectives for Effective Organizational Performance Information Security Management Gutta, Ramamohan Information is a significant asset to organizations, and a data breach from a cyberattack harms reputations and may result in a massive financial loss. Many senior managers lack the competencies to implement an enterprise risk management system and align organizational resources such as people, processes, and technology to prevent cyberattacks on enterprise assets. The purpose of this Delphi study was to explore how the managerial competencies for information security and risk management senior managers help in managing security objectives and practices to mitigate security risks. The National Institute of Standards and Technology framework served as the foundation for this study. The sample was made up of 12 information security practitioners, information security experts, and managers responsible for the enterprise information security management. Participants were from Fortune 500 companies in the United States. Selection was based on their level of experience and knowledge of the topic being studied. Data were collected using a 3 round Delphi study of 12 experts in information security and risk management. Statistical analysis was performed on the collected data during a 3 round Delphi study. The mean, standard deviation, majority agreement, and ranges were used to determine the final concensus for this research study. Findings of this study included the need for managerial support, risk management strategies, and developling the managerial and technical talent to mitigate and respond to cyberattacks. Findings may result in a positive social change by providing information that helps managers to reduce the number of data breaches from cyberattacks, which benefits companies, employees, and customers. 2019-01-01T08:00:00Z text application/pdf https://scholarworks.waldenu.edu/dissertations/7147 https://scholarworks.waldenu.edu/cgi/viewcontent.cgi?article=8426&context=dissertations Walden Dissertations and Doctoral Studies en ScholarWorks Assessing the impact of management support and involvement in organization risk management Cyberattack Financial performance impacts of security breaches Governance Iimpact of information security on firm performance Information security strategy and alignment Databases and Information Systems
collection NDLTD
language en
format Others
sources NDLTD
topic Assessing the impact of management support and involvement in organization risk management
Cyberattack
Financial performance impacts of security breaches
Governance
Iimpact of information security on firm performance
Information security strategy and alignment
Databases and Information Systems
spellingShingle Assessing the impact of management support and involvement in organization risk management
Cyberattack
Financial performance impacts of security breaches
Governance
Iimpact of information security on firm performance
Information security strategy and alignment
Databases and Information Systems
Gutta, Ramamohan
Managing Security Objectives for Effective Organizational Performance Information Security Management
description Information is a significant asset to organizations, and a data breach from a cyberattack harms reputations and may result in a massive financial loss. Many senior managers lack the competencies to implement an enterprise risk management system and align organizational resources such as people, processes, and technology to prevent cyberattacks on enterprise assets. The purpose of this Delphi study was to explore how the managerial competencies for information security and risk management senior managers help in managing security objectives and practices to mitigate security risks. The National Institute of Standards and Technology framework served as the foundation for this study. The sample was made up of 12 information security practitioners, information security experts, and managers responsible for the enterprise information security management. Participants were from Fortune 500 companies in the United States. Selection was based on their level of experience and knowledge of the topic being studied. Data were collected using a 3 round Delphi study of 12 experts in information security and risk management. Statistical analysis was performed on the collected data during a 3 round Delphi study. The mean, standard deviation, majority agreement, and ranges were used to determine the final concensus for this research study. Findings of this study included the need for managerial support, risk management strategies, and developling the managerial and technical talent to mitigate and respond to cyberattacks. Findings may result in a positive social change by providing information that helps managers to reduce the number of data breaches from cyberattacks, which benefits companies, employees, and customers.
author Gutta, Ramamohan
author_facet Gutta, Ramamohan
author_sort Gutta, Ramamohan
title Managing Security Objectives for Effective Organizational Performance Information Security Management
title_short Managing Security Objectives for Effective Organizational Performance Information Security Management
title_full Managing Security Objectives for Effective Organizational Performance Information Security Management
title_fullStr Managing Security Objectives for Effective Organizational Performance Information Security Management
title_full_unstemmed Managing Security Objectives for Effective Organizational Performance Information Security Management
title_sort managing security objectives for effective organizational performance information security management
publisher ScholarWorks
publishDate 2019
url https://scholarworks.waldenu.edu/dissertations/7147
https://scholarworks.waldenu.edu/cgi/viewcontent.cgi?article=8426&context=dissertations
work_keys_str_mv AT guttaramamohan managingsecurityobjectivesforeffectiveorganizationalperformanceinformationsecuritymanagement
_version_ 1719282382850228224