Vis enkel innførsel

dc.contributor.advisorBernsmed, Karinnb_NO
dc.contributor.advisorLine, Marianb_NO
dc.contributor.authorHove, Cathrinenb_NO
dc.contributor.authorTårnes, Martenb_NO
dc.date.accessioned2014-12-19T14:15:29Z
dc.date.available2014-12-19T14:15:29Z
dc.date.created2013-09-24nb_NO
dc.date.issued2013nb_NO
dc.identifier651201nb_NO
dc.identifierntnudaim:8935nb_NO
dc.identifier.urihttp://hdl.handle.net/11250/262845
dc.description.abstractAn increasing use of digital solutions suggests that organizations today are more exposed to attacks than before. Recent reports show that attacks get more advanced and that attackers choose their targets more wisely. Despite preventive measures being implemented, incidents occur occasionally. This calls for effective and efficient information security incident management. Several standards and guidelines addressing incident management exist. However, few studies of current practices have been conducted. In this thesis an empirical study was conducted where organizations' incident management practices were studied. The research was conducted as a case study of three large Norwegian organizations, where the data collection methods were interviews and document studies. Our findings show that the organizations were relatively compliant with standards and guidelines for incident management, but that there was still room for improvements. We found communication, information dissemination, employee involvement, experience and allocation of responsibilities to be important factors to an effective and efficient incident management process. Finally, we contribute with recommendations for performing successful information security incident management. We recommend organizations to use standards and guidelines as a basis for incident management, conduct regular rehearsals, utilize employees as part of the sensor network in incident detection and to conduct awareness campaigns for employees.nb_NO
dc.languageengnb_NO
dc.publisherInstitutt for telematikknb_NO
dc.titleInformation Security Incident Management: An Empirical Study of Current Practicenb_NO
dc.typeMaster thesisnb_NO
dc.source.pagenumber144nb_NO
dc.contributor.departmentNorges teknisk-naturvitenskapelige universitet, Fakultet for informasjonsteknologi, matematikk og elektroteknikk, Institutt for telematikknb_NO


Tilhørende fil(er)

Thumbnail
Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel