2019 International Conference on Cyber Security and Protection of Digital Services (Cyber Security) 2019
DOI: 10.1109/cybersecpods.2019.8884877
|View full text |Cite
|
Sign up to set email alerts
|

Security-Related Stress: A Perspective on Information Security Risk Management

Abstract: In this study, the enactment of information security risk management by novice practitioners is studied by applying an analytical lens of security-related stress. Two organisations were targeted in the study using a case study approach to obtain data about their practices. The study identifies stressors and stress inhibitors in the ISRM process and the supporting ISRM tools and discusses the implications for practitioners. For example, a mismatch between security standards and how they are interpreted in pract… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
3
0

Year Published

2022
2022
2023
2023

Publication Types

Select...
3
1

Relationship

2
2

Authors

Journals

citations
Cited by 4 publications
(3 citation statements)
references
References 40 publications
0
3
0
Order By: Relevance
“…Instead, cybersecurity risk management may overload the agile method since additional requirements introduced between sprints must be assessed [2,3,29,30]. Indeed, cybersecurity risk management activities can consume a lot of time [31,32], which has been reported as a potential stressor for practitioners with little or no previous experience within cybersecurity [33]. We denote this challenge as C 1 .…”
Section: Software Development Life Cyclementioning
confidence: 99%
“…Instead, cybersecurity risk management may overload the agile method since additional requirements introduced between sprints must be assessed [2,3,29,30]. Indeed, cybersecurity risk management activities can consume a lot of time [31,32], which has been reported as a potential stressor for practitioners with little or no previous experience within cybersecurity [33]. We denote this challenge as C 1 .…”
Section: Software Development Life Cyclementioning
confidence: 99%
“…Technostress is defined as psychosomatic illness caused by working with computer technology daily, or the negative psychological link between people and the introduction of new technologies (Wikipedia 2019). The fast-paced workplace, and the continuous changing technological landscape at workplace is shown to cause technostress (Ayyagari R. et al, 2011, Tarafdar, M., Tu, Q., and Ragu-Nathan, T.S., 2010, Lundgren M., and Bergstrom, E., 2019. Workplace-related stress and technostress should be minimised, and this can be achieved by ensuring that operators are not overwhelmed with endless activities and that there is a work life balance.…”
Section: ○ Stressmentioning
confidence: 99%
“…Security controls are typically identified and selected as a result of a risk assessment, often requiring a broad set of skills and knowhow [5][6][7], as it aims to maximize resource allocation as well as benefit the security controls offered in assisting (rather than burdening) organizational operation and development [8]. However, adoption of new security controls often means changes to the organization's environment, which is not always perceived as useful, depending on the organization's change-readiness [9].…”
Section: Introductionmentioning
confidence: 99%