The 2011 Survey of Information Security and Information Assurance Professionals
Yulia Cherdantseva, J. Hilton
Abstract
Yulia Cherdantseva, J. Hilton
Abstract
Information Assurance (IA) is an intensively discussed discipline. Perhaps the most striking feature of IA is that everyone has a different opinion about what it actually is. The literature analysis enables us to distinguish three different approaches to Information Assurance: 1) Technical approach, concentrated on protection of networks; 2) Business approach, where IA is perceived as the comprehensive and systematic management of Information Security (InfoSec); 3) General approach, where IA is considered as a way to establish a level of confidence in information. Interviews with InfoSec practitioners reveal that they interpret the term IA differently and have contradictory views on how IA relates to InfoSec. It was felt that a survey with a greater number of practitioners might help to identify a commonly accepted perception of IA and to clarify the goals of the discipline. In 2011, a survey was conducted among one hundred InfoSec and IA professionals across the world. This chapter presents the results of the survey.
OpenAlex reports 2 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Information Assurance (IA) is an intensively discussed discipline. Perhaps the most striking feature of IA is that everyone has a different opinion about what it actually is. The literature analysis enables us to distinguish three different approaches to Information Assurance: 1) Technical approach, concentrated on protection of networks; 2) Business approach, where IA is perceived as the comprehensive and systematic management of Information Security (InfoSec); 3) General approach, where IA is considered as a way to establish a level of confidence in information. Interviews with InfoSec practitioners reveal that they interpret the term IA differently and have contradictory views on how IA relates to InfoSec. It was felt that a survey with a greater number of practitioners might help to identify a commonly accepted perception of IA and to clarify the goals of the discipline. In 2011, a survey was conducted among one hundred InfoSec and IA professionals across the world. This chapter presents the results of the survey.
Key concepts: Information assurance, Information security, Perception, Knowledge management, Information security management, Information systems security, Computer science, Information system