{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,2]],"date-time":"2025-08-02T19:04:56Z","timestamp":1754161496471,"version":"3.41.2"},"reference-count":35,"publisher":"Emerald","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011,3,22]]},"abstract":"<jats:sec>\n                  <jats:title>Purpose<\/jats:title>\n                  <jats:p>The purpose of this paper is to address three main problems resulting from uncertainty in information security management: dynamically changing security requirements of an organization; externalities caused by a security system; and obsolete evaluation of security concerns.<\/jats:p>\n               <\/jats:sec>\n               <jats:sec>\n                  <jats:title>Design\/methodology\/approach<\/jats:title>\n                  <jats:p>In order to address these critical concerns, a framework based on options reasoning borrowed from corporate finance is proposed and adapted to evaluation of security architecture and decision making for handling these issues at organizational level. The adaptation as a methodology is demonstrated by a large case study validating its efficacy.<\/jats:p>\n               <\/jats:sec>\n               <jats:sec>\n                  <jats:title>Findings<\/jats:title>\n                  <jats:p>The paper shows through three examples that it is possible to have a coherent methodology, building on options theory to deal with uncertainty issues in information security at an organizational level.<\/jats:p>\n               <\/jats:sec>\n               <jats:sec>\n                  <jats:title>Practical implications<\/jats:title>\n                  <jats:p>To validate the efficacy of the methodology proposed in this paper, it was applied to the Spridnings-och H\u00e4mtningssystem (SHS: dissemination and retrieval system) system. The paper introduces the methodology, presents its application to the SHS system in detail and compares it to the current practice.<\/jats:p>\n               <\/jats:sec>\n               <jats:sec>\n                  <jats:title>Originality\/value<\/jats:title>\n                  <jats:p>This research is relevant to information security management in organizations, particularly issues on changing requirements and evaluation in uncertain circumstances created by progress in technology.<\/jats:p>\n               <\/jats:sec>","DOI":"10.1108\/09685221111115836","type":"journal-article","created":{"date-parts":[[2011,3,19]],"date-time":"2011-03-19T08:06:32Z","timestamp":1300521992000},"page":"5-24","source":"Crossref","is-referenced-by-count":15,"title":["Addressing dynamic issues in information security management"],"prefix":"10.1108","volume":"19","author":[{"given":"Haider","family":"Abbas","sequence":"first","affiliation":[{"name":"ECS, ICT, Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christer","family":"Magnusson","sequence":"additional","affiliation":[{"name":"Department of Computer and System Sciences, Stockholm University, Stockholm, Sweden"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Louise","family":"Yngstrom","sequence":"additional","affiliation":[{"name":"Department of Computer and System Sciences, Stockholm University, Stockholm, Sweden"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ahmed","family":"Hemani","sequence":"additional","affiliation":[{"name":"ECS, ICT, Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"key":"#cr-split#-2025072819470816700_b1.1","unstructured":"Abbas, H.  , Yngstr\u00f6m, L. and Hemani, A. (2008), \"Security evaluation of IT products: bridging the gap between common criteria"},{"key":"#cr-split#-2025072819470816700_b1.2","unstructured":"(CC) and real option thinking\", Proceedings of the World Congress on Engineering and Computer Science 2008, San Francisco, CA, USA, 22-24 October, pp. 530-3."},{"key":"2025072819470816700_b5","doi-asserted-by":"crossref","unstructured":"Abbas, H.\n          , Magnusson, C., Yngstr\u00f6m, L. and Hemani, A. (2010), \u201cA structured approach for internalizing externalities caused by IT security mechanisms\u201d, Proceedings of the IEEE International Workshop on Education Technology and Computer Science, Wuhan, China, 6-7 March.","DOI":"10.1109\/ETCS.2010.493"},{"key":"2025072819470816700_b2","doi-asserted-by":"crossref","unstructured":"Abbas, H.\n          , Yngstr\u00f6m, L. and Hemani, A. (2009a), \u201cAdaptability infrastructure for bridging IT security evaluation and options theory\u201d, Proceedings of the 2nd IEEE\/ACM International Conference on Security of Information and Networks (SIN 2009), Gazimagusa, 6-10 October, pp. 39-45.","DOI":"10.1145\/1626195.1626208"},{"key":"2025072819470816700_b3","unstructured":"Abbas, H.\n          , Yngstr\u00f6m, L. and Hemani, A. (2009b), \u201cEmpowering security evaluation of IT products with options theory\u201d, paper presented at the 30th IEEE Symposium on Security and Privacy, Oakland, CA, 17-20 May."},{"key":"2025072819470816700_b4","doi-asserted-by":"crossref","unstructured":"Abbas, H.\n          , Yngstr\u00f6m, L. and Hemani, A. (2009c), \u201cOption based evaluation: security evaluation of IT products based on options theory\u201d, Proceedings of IEEE Eastern European Regional Conference on the Engineering of Computer Based Systems, Novi Sad, Serbia, 7-8 September, pp. 134-41.","DOI":"10.1109\/ECBS-EERC.2009.27"},{"key":"2025072819470816700_b7","doi-asserted-by":"crossref","unstructured":"Brynjolfsson, E.\n           and Yang, S. (1996), \u201cInformation technology and productivity: a review of the literature\u201d, Advances in Computers, Vol. 43, Academic Press, New York, NY, pp. 179-214.","DOI":"10.1016\/S0065-2458(08)60644-0"},{"key":"2025072819470816700_b6","unstructured":"Byrnes, C.\n           and Kyratzoglou, L. (2008), \u201cApplying architecture tradeoff assessment method (ATAM) as part of formal software architecture review\u201d, MITRE Corporation, available at: www.sei.cmu.edu\/architecture\/saturn\/2008\/presentations\/SATURN_ATAM_assessment.pdf (accessed 15 December 2009)."},{"key":"2025072819470816700_b13","unstructured":"CC Portal\n           (2009a), \u201cCRA Members, 2009\u201d, available at: www.commoncriteriaportal.org\/members.html (accessed 14 December 2009)."},{"key":"2025072819470816700_b9","unstructured":"CC Portal\n           (2009b), \u201cIntroduction and general model\u201d, Version 3.1 Revision 3 Final, available at: www.commoncriteriaportal.org\/ (accessed 15 November 2009)."},{"key":"2025072819470816700_b11","unstructured":"Cavoukian, A.\n           (2009), \u201cPrivacy as a negative externality the solution: privacy by design\u201d, Proceedings of Workshop on the Economics of Information Security, London, UK."},{"key":"2025072819470816700_b8","doi-asserted-by":"crossref","unstructured":"Chatterjee, D.\n           and Ramesh, V. (1999), \u201cReal options for risk management in information technology projects\u201d, Proceedings of the Thirty-Second Annual Hawaii International Conference on System Sciences, Maui, HI, Vol. 7.","DOI":"10.1109\/HICSS.1999.772829"},{"issue":"October","key":"2025072819470816700_b12","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1086\/466560","article-title":"The problem of social cost","volume":"3","author":"Coase","year":"1960","journal-title":"Journal of Law & Economics"},{"key":"2025072819470816700_b10","doi-asserted-by":"crossref","unstructured":"Cornes, R.\n           and Sandler, T. (1996), The Theory of Externalities, Public Goods and Club Goods, Cambridge University Press, Cambridge.","DOI":"10.1017\/CBO9781139174312"},{"key":"2025072819470816700_b14","unstructured":"Dunsire, K.\n          , O'Neill, T., Denford, M. and Leaney, J. (2005), \u201cThe ABACUS architectural approach to computer-based system and enterprise evolution\u201d, Proceedings of the 12th IEEE International Conference and Workshops on the Engineering of Computer-based Systems (ECBS'05), Greenbelt, MD, USA."},{"key":"2025072819470816700_b16","unstructured":"Faboozi, F.J.\n           (2007), \u201cComparison between real option valuation & discounted cash flow valuation\u201d, available at: www.associatedcontent.com\/article\/327842\/comparison_between_real_option_valuation.html (accessed 13 September 2009)."},{"issue":"3","key":"2025072819470816700_b18","first-page":"1","article-title":"Information security and real options: a wait-and-see approach","volume":"19","author":"Gordon","year":"2003","journal-title":"Computer Security Journal"},{"key":"2025072819470816700_b15","unstructured":"Hagsten, E.\n           (2009), \u201cHuman capital, information technology and productivity\u201d, paper presented at the Statistics Sweden, Investments in the Future 2, International Statistical Conference, Prague, 14-15 September."},{"key":"2025072819470816700_b19","unstructured":"Harvey, C.R.\n           (1999), \u201cIdentifying real options\u201d, Fuqua School of Business, Duke University, Durham, NC, availbale at: http:\/\/faculty.fuqua.duke.edu\/\u223ccharvey\/Teaching\/BA45_2002\/Identifying_real_options.htm (accessed 15 April 2009)."},{"key":"2025072819470816700_b20","unstructured":"Helenelund, K.\n          , Urdell, S., Sehlberg, B., Bremsj\u00f6, A., Lindgren, A., Lundh, J. and Marklund, C. (2007), SHS Version 1.2 Protocols, VERVA \u2013 Swedish Administrative Development Agency, Stockholm."},{"key":"2025072819470816700_b21","unstructured":"Jackson, W.\n           (2009), \u201cUnder attack common criteria has loads of critics, but is it getting a bum rap?\u201d, available at: www.gcn.com\/print\/26_21\/44857-1.html (accessed April 2009)."},{"key":"2025072819470816700_b22","doi-asserted-by":"crossref","unstructured":"Kazman, R.\n           and Klein, M. (2000), \u201cDesigning and analyzing software architectures using ABASs\u201d, Proceedings of the 22nd International Conference on Software Engineering (ICSE'00), Limerick, Ireland June, p. 820.","DOI":"10.1145\/337180.337836"},{"key":"2025072819470816700_b23","doi-asserted-by":"crossref","unstructured":"Li, J.\n           and Su, X. (2007), \u201cMaking cost effective security decision with real option thinking\u201d, Proceedings of the International Conference on Software Engineering Advances (ICSEA 2007), Cap Esterel, France, 25-31 August.","DOI":"10.1109\/ICSEA.2007.50"},{"key":"2025072819470816700_b24","doi-asserted-by":"crossref","unstructured":"Maxwell, C.\n          , Leaney, J. and O'Neill, T. (2008), \u201cUtilising abstract matching to preserve the nature of heuristics in design optimization\u201d, Proceedings of the 15th Annual IEEE International Conference and Workshop on the Engineering of Computer-based Systems, Belfast, Ireland, 31 March-4 April.","DOI":"10.1109\/ECBS.2008.29"},{"key":"2025072819470816700_b25","unstructured":"Mun, J.\n           (2005), Real Options Analysis: Tools and Techniques for Valuing Strategic Investments and Decisions, 2nd ed., Wiley, New York, NY."},{"key":"2025072819470816700_b26","unstructured":"National Security Agency\n           (2008), \u201cCommon criteria evaluation and validation scheme, assurance continuity, guidance for maintenance and re-evaluation\u201d, 8 September, Publication No. 6, version 2.0, availablbe at: www.niap-ccevs.org\/policy\/ccevs\/scheme-pub-6.pdf (accessed 24 March 2009)."},{"key":"2025072819470816700_b17","unstructured":"NIST\n           (2006), Minimum Security Requirement for Federal Information and Information System, Computer Security Division, Information Technology Laboratory, National Institute of Standards and Technology, Gaithersburg, MD, 20899-8930, FIPS PUB 200, March available at: http:\/\/csrc.nist.gov\/publications\/fips\/fips200\/FIPS-200-final-march.pdf."},{"key":"2025072819470816700_b27","doi-asserted-by":"crossref","unstructured":"Ozkaya, I.\n          , Kazman, R. and Klein, M. (2007), \u201cQuality-attribute based economic valuation of architectural patterns\u201d, Proceedings of the First International Workshop on the Economics of Software and Computation. International Conference on Software Engineering, IEEE Computer Society, Washington, DC, USA, 20-26 May.","DOI":"10.1109\/ESC.2007.8"},{"key":"2025072819470816700_b29","doi-asserted-by":"crossref","unstructured":"Parakhine, A.\n          , Leaney, J. and O'Neill, T. (2008), \u201cDesign guidance using simulation-based Bayesian belief networks\u201d, Proceedings of the 15th Annual IEEE International Conference and Workshop on the Engineering of Computer-based Systems, Belfast, USA.","DOI":"10.1109\/ECBS.2008.28"},{"key":"2025072819470816700_b30","doi-asserted-by":"crossref","unstructured":"Raza, A.\n          , Abbas, H., Yngstr\u00f6m, L. and Hemani, A. (2009), \u201cSecurity characterization for evaluation of software architectures using ATAM\u201d, Proceedings of the IEEE International Conference on Information and Communication Technologies, Karachi, Pakistan, 15-16 August, pp. 241-6.","DOI":"10.1109\/ICICT.2009.5267185"},{"key":"2025072819470816700_b31","unstructured":"Schneier, B.\n           (2008), Schneier on Security, Wiley, New York, NY."},{"key":"2025072819470816700_b32","unstructured":"Software Test Plan Template\n           (2009), available at: www.docstoc.com\/docs\/4352427\/Software-Test-Plan-Template (accessed 21 September 2009)."},{"key":"2025072819470816700_b33","doi-asserted-by":"crossref","unstructured":"Tansey, B.\n           and Stroulia, E. (2007), \u201cValuating software service development: integrating COCOMO II and real options theory\u201d, International Workshop on the Economics of Software and Computation, Co-located with ICSE 2007 Proceedings of IEEE International Conference on Software Engineering, Minneapolis, MN.","DOI":"10.1109\/ESC.2007.11"},{"key":"2025072819470816700_b34","doi-asserted-by":"crossref","unstructured":"Zhu, J.\n          , Liang, Y. and Gu, Y. (2008), \u201cThe requirements change analysis for different level users\u201d, Proceedings of the IEEE International Symposium on Intelligent Information Technology Application Workshops, Shanghai, China, 21-22 December, pp. 987-9.","DOI":"10.1109\/IITA.Workshops.2008.204"},{"key":"2025072819470816700_frd1","unstructured":"Ozkaya, I.\n           (2009), \u201cUMSEC Colloquium: applying real-options theory to software architecture design decision making\u201d, available at: www.umsec.umn.edu\/events\/UMSEC-Colloquium-Applying-Real-Options-Theory-Soft (accessed 23 September 2009)."}],"container-title":["Information Management &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/09685221111115836","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/09685221111115836\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/ics\/article-pdf\/19\/1\/5\/1215966\/09685221111115836.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/www.emerald.com\/ics\/article-pdf\/19\/1\/5\/1215966\/09685221111115836.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,28]],"date-time":"2025-07-28T23:47:22Z","timestamp":1753746442000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.emerald.com\/ics\/article\/19\/1\/5\/178568\/Addressing-dynamic-issues-in-information-security"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,3,22]]},"references-count":35,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2011,3,22]]}},"URL":"https:\/\/doi.org\/10.1108\/09685221111115836","relation":{},"ISSN":["0968-5227","1758-5805"],"issn-type":[{"type":"print","value":"0968-5227"},{"type":"electronic","value":"1758-5805"}],"subject":[],"published":{"date-parts":[[2011,3,22]]}}}