{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:37:52Z","timestamp":1781105872050,"version":"3.54.1"},"reference-count":47,"publisher":"IGI Global Scientific Publishing","issue":"2","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014,4,1]]},"abstract":"<p>Contemporary methods for assessing information security risks have adopted mainly technical views on information and technology assets. Organizational dynamics of information management and knowledge sharing have gained less attention. This article outlines a new, genre-based, approach to information security risk assessment in order to orientate toward organization- and knowledge-centric identification and analysis of security risks. In order to operationalize the genre-based approach, we suggest the use of a genre-based analytical method for identifying organizational communication patterns through which organizational knowledge is shared. The genre-based method is then complemented with tasks and techniques from a textbook risk assessment method (OCTAVE Allegro). We discuss the initial experiences of three experienced information security professionals who tested the method. The article concludes with implications of the genre-based approach to analyzing information and knowledge security risks for future research and practice.<\/p>","DOI":"10.4018\/ijkm.2014040102","type":"journal-article","created":{"date-parts":[[2014,11,3]],"date-time":"2014-11-03T07:59:17Z","timestamp":1415001557000},"page":"13-27","source":"Crossref","is-referenced-by-count":5,"title":["Genre-Based Approach to Assessing Information and Knowledge Security Risks"],"prefix":"10.4018","volume":"10","author":[{"given":"Ali Mohammad","family":"Padyab","sequence":"first","affiliation":[{"name":"Lule\u00e5 University of Technology, Lule\u00e5, Sweden"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tero","family":"P\u00e4iv\u00e4rinta","sequence":"additional","affiliation":[{"name":"Lule\u00e5 University of Technology, Lule\u00e5, Sweden"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dan","family":"Harnesk","sequence":"additional","affiliation":[{"name":"Lule\u00e5 University of Technology, Lule\u00e5, Sweden"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"ijkm.2014040102-0","doi-asserted-by":"publisher","DOI":"10.1109\/TENCON.2005.301322"},{"key":"ijkm.2014040102-1","doi-asserted-by":"publisher","DOI":"10.2307\/3250961"},{"key":"ijkm.2014040102-2","author":"C.Alberts","year":"2004","journal-title":"Managing Information Security Risks"},{"key":"ijkm.2014040102-3","doi-asserted-by":"crossref","DOI":"10.21236\/ADA634134","author":"C.Alberts","year":"2003","journal-title":"Introduction to the OCTAVE Approach (Tech. Rep.)"},{"key":"ijkm.2014040102-4","doi-asserted-by":"crossref","unstructured":"Alberts, C. J., Behrens, S. G., Pethia, R. D., & Wilson, W. R. (1999). Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE) Framework, Version 1.0 (Tech. Rep. No. CMU\/SEI-99-TR-017). Pittsburgh, PA: Carnegie Mellon University","DOI":"10.21236\/ADA367718"},{"key":"ijkm.2014040102-5","doi-asserted-by":"publisher","DOI":"10.1145\/958160.958209"},{"key":"ijkm.2014040102-6","doi-asserted-by":"publisher","DOI":"10.1145\/162124.162127"},{"key":"ijkm.2014040102-7","unstructured":"Campbell, P. L., & Stamp, J. E. (2004). A classification scheme for risk assessment methods (Tech. Rep. No. SAND2004-4233). Albuquerque, NM: Sandia National Laboratory."},{"key":"ijkm.2014040102-8","doi-asserted-by":"crossref","unstructured":"Caralli, R., Stevens, J., Young, L., & Wilson, W. (2007). Introducing OCTAVE Allegro: Improving the Information Security Risk Assessment Process (Tech. Rep. No. CMU\/SEI-2007-TR-012). Pittsburgh, PA: Carnegie Mellon University.","DOI":"10.21236\/ADA470450"},{"key":"ijkm.2014040102-9","doi-asserted-by":"publisher","DOI":"10.1145\/320434.320440"},{"key":"ijkm.2014040102-10","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-46000-4_13"},{"key":"ijkm.2014040102-11","doi-asserted-by":"publisher","DOI":"10.1080\/01972240050133652"},{"key":"ijkm.2014040102-12","author":"K. C.Desouza","year":"2007","journal-title":"Managing knowledge security: strategies for protecting your company's intellectual assets"},{"key":"ijkm.2014040102-13","doi-asserted-by":"publisher","DOI":"10.1145\/341852.341877"},{"key":"ijkm.2014040102-14","doi-asserted-by":"publisher","DOI":"10.1046\/j.1365-2575.2001.00099.x"},{"key":"ijkm.2014040102-15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-12544-7_16"},{"key":"ijkm.2014040102-16","doi-asserted-by":"publisher","DOI":"10.1109\/CISDA.2007.368155"},{"key":"ijkm.2014040102-17","doi-asserted-by":"publisher","DOI":"10.1111\/0272-4332.212106"},{"key":"ijkm.2014040102-18","doi-asserted-by":"publisher","DOI":"10.1002\/0471723908"},{"key":"ijkm.2014040102-19","doi-asserted-by":"publisher","DOI":"10.1108\/09685229610114178"},{"key":"ijkm.2014040102-20","unstructured":"Houmb, S. H., Den Braber, F., Lund, M. S., & St\u00f8len, K. (2002). Towards a UML profile for model-based risk assessment. In J. Jurjens, V. Cengarle, E. Fernandez, B. Rumpe, and R. Sandner (Eds.), Critical systems development with UML-Proceedings of the UML\u201902 workshop (Tech. Rep. No. TUM-I0208) (pp. 79-91). Munich, Bavaria: Munich University of Technology."},{"key":"ijkm.2014040102-21","doi-asserted-by":"publisher","DOI":"10.1108\/VINE-07-2012-0028"},{"key":"ijkm.2014040102-22","doi-asserted-by":"publisher","DOI":"10.1007\/s10796-007-9053-4"},{"key":"ijkm.2014040102-23","author":"A.Jones","year":"2005","journal-title":"Risk management for computer security: Protecting your network & information assets"},{"key":"ijkm.2014040102-24","unstructured":"Karjalainen, A., P\u00e4iv\u00e4rinta, T., Tyrv\u00e4inen, P., & Rajala, J. (2000). Genre-based metadata for enterprise document management. In Proceedings of the 33rd Annual Hawaii International Conference on System Sciences, vol. 2 (pp. 3013-3023). Los Alamos, CA: IEEE Computer Society Press."},{"key":"ijkm.2014040102-25","doi-asserted-by":"publisher","DOI":"10.1108\/09685229610130503"},{"key":"ijkm.2014040102-26","doi-asserted-by":"publisher","DOI":"10.1046\/j.1365-2575.1999.00051.x"},{"key":"ijkm.2014040102-27","unstructured":"Masera, M., & Fovino, I. N. (2006). Modelling information assets for security risk assessment in industrial settings. In 15th EICAR Annual Conference Proceeding (p. 137-149). Cesson: Ecole Superieure et d'Application des Transmissions."},{"key":"ijkm.2014040102-28","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45831-X_7"},{"key":"ijkm.2014040102-29","unstructured":"Merriam-Webster Online Dictionary. (2014). Retrieved August 25, 2014, from http:\/\/www.merriam-webster.com\/dictionary\/genre"},{"key":"ijkm.2014040102-30","unstructured":"NIST SP 800-39 (2001). Managing Information Security risks, National Institute of Standards and Technology. Retrieved August 21, 2014, from http:\/\/csrc.nist.gov\/publications\/nistpubs\/800-39\/SP800-39-final.pdf"},{"key":"ijkm.2014040102-31","doi-asserted-by":"publisher","DOI":"10.1287\/orsc.5.1.14"},{"key":"ijkm.2014040102-32","doi-asserted-by":"publisher","DOI":"10.1016\/S0167-4048(00)07020-6"},{"key":"ijkm.2014040102-33","doi-asserted-by":"publisher","DOI":"10.2307\/2393771"},{"key":"ijkm.2014040102-34","doi-asserted-by":"publisher","DOI":"10.1016\/S1471-7727(01)00002-1"},{"key":"ijkm.2014040102-35","doi-asserted-by":"publisher","DOI":"10.4018\/978-1-878289-77-3.ch005"},{"key":"ijkm.2014040102-36","doi-asserted-by":"crossref","DOI":"10.1201\/9781420031195","author":"T. R.Peltier","year":"2005","journal-title":"Information security risk analysis"},{"key":"ijkm.2014040102-37","unstructured":"Saaren-Sepp\u00e4l\u00e4, K. (1997). Sein\u00e4tekniikka prosessien kehitt\u00e4misess\u00e4. (Using the wall-chart technique in process development, in Finnish) Finland: Kari Saaren-Sepp\u00e4l\u00e4 Ltd."},{"key":"ijkm.2014040102-38","unstructured":"Shedden, P., Ahmad, A., & Ruighaver, A. B. (2006, April). Risk Management Standard-the Perception of Ease of Use. Paper presented at the 5th Annual Security Conference, Las Vegas, NV."},{"key":"ijkm.2014040102-39","doi-asserted-by":"publisher","DOI":"10.1108\/03055721111134790"},{"key":"ijkm.2014040102-40","first-page":"127","article-title":"Information Security Risk Assessment: Towards a Business Practice Perspective.","author":"P.Shedden","year":"2010","journal-title":"Proceedings of the 8th Information Security Management Conference"},{"key":"ijkm.2014040102-41","first-page":"185","article-title":"A holistic risk analysis method for identifying information security risks","author":"J. L.Spears","year":"2006","journal-title":"Security Management, Integrity, and Internal Control in Information Systems"},{"key":"ijkm.2014040102-42","author":"A.Strauss","year":"1990","journal-title":"Basics of Qualitative Research: Grounded Theory Procedures and Techniques"},{"key":"ijkm.2014040102-43","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2003.1174838"},{"key":"ijkm.2014040102-44","unstructured":"Visintine, V. (2003). An Introduction to Information Risk Assessment, SANS Institute, 8."},{"issue":"2","key":"ijkm.2014040102-45","doi-asserted-by":"crossref","first-page":"299","DOI":"10.2307\/258774","article-title":"Genres of organizational communication: A structurational approach to studying communication and media.","volume":"17","author":"J.Yates","year":"1992","journal-title":"Academy of Management Review"},{"key":"ijkm.2014040102-46","author":"E.Yourdon","year":"1989","journal-title":"Modern structured analysis"}],"container-title":["International Journal of Knowledge Management"],"original-title":[],"language":"ng","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=117902","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,1]],"date-time":"2022-06-01T11:55:25Z","timestamp":1654084525000},"score":1,"resource":{"primary":{"URL":"https:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/ijkm.2014040102"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2014,4,1]]},"references-count":47,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2014,4]]}},"URL":"https:\/\/doi.org\/10.4018\/ijkm.2014040102","relation":{},"ISSN":["1548-0666","1548-0658"],"issn-type":[{"value":"1548-0666","type":"print"},{"value":"1548-0658","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,4,1]]}}}