Informal learning in security incident response teams

P Shedden, A Ahmad, AB Ruighaver - 2011 - aisel.aisnet.org
P Shedden, A Ahmad, AB Ruighaver
2011aisel.aisnet.org
Abstract Information security incident response is a critical security process for organisations
aiming to provide an effective capability to recover from information security attacks. A critical
component of security incident response methodologies is the ability to learn from security
incidents on how to improve the incident response process in particular and security
management in general. Best-practice methodologies and existing research in this area
view the incident response process as highly formal and structured while providing …
Abstract
Information security incident response is a critical security process for organisations aiming to provide an effective capability to recover from information security attacks. A critical component of security incident response methodologies is the ability to learn from security incidents on how to improve the incident response process in particular and security management in general. Best-practice methodologies and existing research in this area view the incident response process as highly formal and structured while providing recommendations on learning in formal feedback sessions at the conclusion of the incident investigation. This contrasts with more general organizational learning literature that suggests learning in organizations is frequently informal, incidental and ongoing. This research-in-progress paper describes the first phase of a project. Results from a focus group of experts indicates that response to incidents is largely informal suggesting a new Incident Response model is needed that incorporates informal learning practices.
aisel.aisnet.org
Showing the best result for this search. See all results