Digitala Vetenskapliga Arkivet

Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Information security risk management tools in the air traffic management domain: what are practitioners’ needs?
Luleå University of Technology, Department of Computer Science, Electrical and Space Engineering, Digital Services and Systems.ORCID iD: 0000-0002-4057-9454
School of Engineering, Jönköping University, Jönköping, Sweden.
School of Informatics, University of Skövde, Skövde, Sweden.
SINTEF Digital, Trondheim, Norway.
Show others and affiliations
2025 (English)In: Information Security Journal, ISSN 1939-3555, E-ISSN 1939-3547Article in journal (Refereed) Epub ahead of print
Abstract [en]

Information Security Risk Management (ISRM) activities are essential for organizations seeking to control and monitor risk. However, it is well known that doing so is difficult, and the different ISRM activities provide different challenges. To provide support, ISRM tools can be used. Such tools can come in the form of spreadsheets, document templates, or dedicated software to support either part of or the full ISRM work. Few studies have been conducted investigating the use of such tools and their necessary properties. Through semi-structured interviews with 17 security practitioners in the Air Traffic Management (ATM) domain and five validation sessions with 34 experts, this study examines the needs of security practitioners using ISRM tools. The ATM domain was chosen as the study context since they use a method built on the ISO/IEC 27005 standard, which, unlike other ISRM frameworks, does not provide tool support. The findings contain a collection of properties needed in ISRM tools. Notably, the ability to get a holistic view of risks in and toward the organization, tool flexibility, and the ability to get assistance with documentation and information exchange. We also identify that current ISRM tools do not provide enough support and suggest ways to address this. 

Place, publisher, year, edition, pages
Taylor & Francis, 2025.
Keywords [en]
Air traffic management, aviation, cybersecurity, information security risk management, security practitioner
National Category
Information Systems, Social aspects
Research subject
Information Systems
Identifiers
URN: urn:nbn:se:ltu:diva-112600DOI: 10.1080/19393555.2025.2498472OAI: oai:DiVA.org:ltu-112600DiVA, id: diva2:1956724
Note

Full text: CC BY license;

Funder: Swedish Civil Contingencies Agency (MSB), project VISKA (MSB 2021-14650); SESAR JU under the EU H2020 research and innovation program (grant agreement 731765); Interreg [20357977];

Available from: 2025-05-07 Created: 2025-05-07 Last updated: 2025-05-07

Open Access in DiVA

fulltext(941 kB)22 downloads
File information
File name FULLTEXT01.pdfFile size 941 kBChecksum SHA-512
5a70b0ada279d07149c19a585f4eae70344c14e7e77b48ae38bd16216deb21a3ac6fdb08c097ccb574e38022a1ca90657ed04c0fb459a8a14a518b69f4c63fe4
Type fulltextMimetype application/pdf

Other links

Publisher's full text

Search in DiVA

By author/editor
Andersson, Simon
By organisation
Digital Services and Systems
In the same journal
Information Security Journal
Information Systems, Social aspects

Search outside of DiVA

GoogleGoogle Scholar
Total: 26 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 96 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf