Analysis of the Next Evolution of Security Audit Criteria
Nykänen, R., Kelo, T., & Kärkkäinen, T. (2023). Analysis of the Next Evolution of Security Audit Criteria. Journal of Information Warfare, 22(4), 25-39. https://www.jinfowar.com/journal/volume-22-issue-4/analysis-next-evolution-security-audit-criteria
Published in
Journal of Information WarfareDate
2023Copyright
© 2024 the Authors
Security assessments are performed for multiple reasons, including compliance with the information security regulation. Amongst other objectives, regulatory requirements are created to increase the resilience of national infrastructure and protect against information and cybersecurity threats. When the regulatory requirements are revised, the security audit criteria also need to be updated and validated. This was also the case with the Julkri, criteria developed for the conformance assessments of the renewed Finnish information security regulation. In this article, a comparative evaluation based on Design Science Research is performed to determine whether the new Julkri criteria improve existing criteria and control catalogues.
Publisher
ArmisteadTECISSN Search the Publication Forum
1445-3312Keywords
Original source
https://www.jinfowar.com/journal/volume-22-issue-4/analysis-next-evolution-security-audit-criteriaPublication in research information system
https://converis.jyu.fi/converis/portal/detail/Publication/207657282
Metadata
Show full item recordCollections
License
Related items
Showing items with similar title or keywords.
-
Measuring users' level of information security awareness : research and development of sample questions
Mäkitalo, Hermanni (2017)Tämän gradun tarkoituksena on käsiteanalyysin avulla hahmottaa tärkeimpiä omaisuuksia tietoturvatietoisuudesta ja tavoista levittää sitä, tutustua niihin tarkemmin, ja muodostaa näistä perusteltuja ja käyttäjille olennaisia ... -
Dealing with Complexity in Design Science Research : A Methodology Using Design Echelons
Tuunanen, Tuure; Winter, Robert; vom Brocke, Jan (Society for Management Information Systems, 2024)Design science research (DSR) aims to generate knowledge about innovative solutions to real-world problems. Consequently, DSR needs to deal with the complexity related to problem and solution spaces involving sociotechnical ... -
Common Misunderstandings of Deterrence Theory in Information Systems Research and Future Research Directions
Siponen, Mikko; Soliman, Wael; Vance, Anthony (ACM, 2022)In the 1980s, information systems (IS) borrowed deterrence theory (DT) from the field of criminology to explain information security behaviors (or intention). Today, DT is among the most commonly used theories in IS security ... -
Immersive Virtual Reality Education Application : Four Development Iterations along Design Science Research Methodology
Holopainen, Jani; Lähtevänoja, Antti; Tuunanen, Tuure (University of Hawaii at Manoa, 2022)This study introduces a research and development process of an immersive Virtual Reality (VR) education application. Altogether four application development iterations are showcased along the Design Science Research ... -
The Design Science Research Process : A Model for Producing and Presenting Information Systems Research
Peffers, Ken; Tuunanen, Tuure; Gengler, Charles E.; Rossi, Matti; Hui, Wendy; Virtanen, Ville; Bragge, Johanna (Claremont Graduate University, 2006)The authors design and demonstrate a process for carrying out design science (DS) research in information systems and demonstrate use of the process to conduct research in two case studies. Several IS researchers have ...