Investigation into the State-of-Practice of Operations Security Management Based on ISO/IEC 27002
Winfred Yaokumah
Additional contact information
Winfred Yaokumah: Department of Information Technology, Pentecost University College, Accra, Ghana
International Journal of Technology Diffusion (IJTD), 2016, vol. 7, issue 1, 53-72
Abstract:
This study assessed information security management in organizations through a questionnaire based on the ISO/IEC 27002, with special focus on operations security. A survey with cross-sectional research design was conducted and data collected from 223 participants from 56 organizations. Overall, the level of operations security maturity was 61.2%, which is the maturity Level 3 (well-defined). This level suggested that operations security controls and processes were documented, approved, and implemented organization-wide. Backups and malware protection were the most implemented security controls, while logging, auditing and monitoring were the least implemented controls. Assessment of inter-organizational operations security found significant differences among the organizations. Financial and Health Care Institutions outperform Educational Institutions and Government Public Service. The study provided insight into maturity levels of operations security controls and the results useful for benchmarking inter-organizational performance, competitiveness and improvement in information security.
Date: 2016
References: Add references at CitEc
Citations:
Downloads: (external link)
http://services.igi-global.com/resolvedoi/resolve. ... 4018/IJTD.2016010104 (application/pdf)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:igg:jtd000:v:7:y:2016:i:1:p:53-72
Access Statistics for this article
International Journal of Technology Diffusion (IJTD) is currently edited by Ali Hussein Saleh Zolait
More articles in International Journal of Technology Diffusion (IJTD) from IGI Global
Bibliographic data for series maintained by Journal Editor ().