Open this publication in new window or tab >>Show others...
2025 (English)In: Information Security Journal, ISSN 1939-3555, E-ISSN 1939-3547, Vol. 34, no 6, p. 561-578Article in journal (Refereed) Published
Abstract [en]
Information Security Risk Management (ISRM) activities are essential for organizations seeking to control and monitor risk. However, it is well known that doing so is difficult, and the different ISRM activities provide different challenges. To provide support, ISRM tools can be used. Such tools can come in the form of spreadsheets, document templates, or dedicated software to support either part of or the full ISRM work. Few studies have been conducted investigating the use of such tools and their necessary properties. Through semi-structured interviews with 17 security practitioners in the Air Traffic Management (ATM) domain and five validation sessions with 34 experts, this study examines the needs of security practitioners using ISRM tools. The ATM domain was chosen as the study context since they use a method built on the ISO/IEC 27005 standard, which, unlike other ISRM frameworks, does not provide tool support. The findings contain a collection of properties needed in ISRM tools. Notably, the ability to get a holistic view of risks in and toward the organization, tool flexibility, and the ability to get assistance with documentation and information exchange. We also identify that current ISRM tools do not provide enough support and suggest ways to address this.
Place, publisher, year, edition, pages
Taylor & Francis Group, 2025
Keywords
Air traffic management, aviation, cybersecurity, information security risk management, security practitioner
National Category
Computer and Information Sciences
Research subject
Information Systems
Identifiers
urn:nbn:se:his:diva-25152 (URN)10.1080/19393555.2025.2498472 (DOI)001482570800001 ()2-s2.0-105004473907 (Scopus ID)
Funder
Interreg, 20357977Swedish Civil Contingencies Agency, MSB 2021-14650Interreg, 731765
Note
CC BY 4.0
Simon Andersson simon.andersson@ltu.se Computer Science, Electrical and Space Engineering, Luleå University of Technology,Laboratorievägen 14, LULEÅ SE-971 87, Sweden
The work was supported by the Interreg [20357977]; The Swedish Civil Contingencies Agency [MSB 2021–14650]; SESAR Joint Undertaking [731765].
2025-05-152025-05-152025-10-29Bibliographically approved