Change search
ReferencesLink to record
Permanent link

Direct link
Towards More Structured Information Asset Identification Approach for Risk Assessment Methods: Using Genre Based Method
2013 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

Information asset identification is a preparatory phase in every risk assessment method which makes the basis for identifying risks associated to those assets. Current risk assessment methods have deficiencies to provide a structured approach towards identifying information assets. They take a stance of what an information asset is than how to identify one. On the other hand they ignore dynamic work environment to acknowledge employees as the knowledgeable entities within the organization. Although current literature enumerates current risk assessment limitations with respect to their approaches towards information asset identification, but it lacks a systematic approach to map information assets. In this research we proposed that Genre Based Method (GBM) can fulfil the gap. For this reason we utilized GBM into a lightweight risk assessment method, OCTAVE Allegro. The proposed method was tried out by two CISOs and one Principal located in three different companies. It was suggested that GBM could be used in parallel with OCTAVE Allegro during the information asset mapping with the help of producers and users of information (PUI) or their representatives. PUI entities participate in a social debate to scrutinize genres in which they transfer information with the help of supported tools like diagonal matrix and genre worksheet. Further on, identified information assets are fed into OCTAVE Allegro for further risk assessment. The result shows that GBM’s supported tools and guidelines can identify channels of communication where there is a potential leakage. This paper therefore suggests that GBM can facilitate enumeration of information assets through channels of communications or genres.

Place, publisher, year, edition, pages
Keyword [en]
Technology, Information asset identification, Information asset mapping, risk assessment, Genre Based Method, Grounded theory
Keyword [sv]
URN: urn:nbn:se:ltu:diva-42578Local ID: 091d1b0c-bffd-487d-afdf-218794001000OAI: diva2:1015801
Subject / course
Student thesis, at least 30 credits
Educational program
Computer Science and Engineering, master's level
Validerat; 20130225 (global_studentproject_submitter)Available from: 2016-10-04 Created: 2016-10-04Bibliographically approved

Open Access in DiVA

fulltext(1216 kB)7 downloads
File information
File name FULLTEXT02.pdfFile size 1216 kBChecksum SHA-512
Type fulltextMimetype application/pdf

Search in DiVA

By author/editor
Padyab, Ali Mohammad

Search outside of DiVA

GoogleGoogle Scholar
Total: 7 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

Total: 3 hits
ReferencesLink to record
Permanent link

Direct link