Article ID: | iaor20063291 |
Country: | United Kingdom |
Volume: | 14 |
Issue: | 3 |
Start Page Number: | 303 |
End Page Number: | 315 |
Publication Date: | Sep 2005 |
Journal: | European Journal of Information Systems |
Authors: | Siponen Mikko T. |
Keywords: | computers: information |
Scholars have developed several modern information systems security (ISS) methods. Yet the traditional ISS methods – SS checklists, ISS standards, ISS maturity criteria, risk management (RM) and formal methods (FM) – are still among the most used ISS methods. This study makes sense of these traditional ISS methods by comparing their underlying key assumptions. The main finding is that the traditional ISS methods regurgitate several features and assumptions that are required to be dealt with by traditional ISS methods developers and practitioners.