SwePub
Sök i LIBRIS databas

  Utökad sökning

onr:"swepub:oai:DiVA.org:his-19309"
 

Sökning: onr:"swepub:oai:DiVA.org:his-19309" >

Developing an information classification method

Bergström, Erik, 1976- (författare)
Jönköping University,JTH, Avdelningen för datateknik och informatik,School of Engineering, Jönköping University, Sweden
Karlsson, Fredrik, 1974- (författare)
Örebro universitet,Handelshögskolan vid Örebro Universitet,Informatik,School of Business, Örebro University, Örebro, Sweden
Åhlfeldt, Rose-Mharie, 1960- (författare)
Högskolan i Skövde,Institutionen för informationsteknologi,Forskningsmiljön Informationsteknologi,Informationssystem (IS), Information Systems,School of Informatics, University of Skövde, Skövde, Sweden
 (creator_code:org_t)
Emerald Group Publishing Limited, 2021
Engelska.
Ingår i: Information and Computer Security. - : Emerald Group Publishing Limited. - 2056-4961. ; 29:2, s. 209-239
  • Tidskriftsartikel (refereegranskat)
Abstract Ämnesord
Stäng  
  • Purpose: The purpose of this paper is to develop a method for information classification. The proposed method draws on established standards, such as the ISO/IEC 27002 and information classification practices. The long-term goal of the method is to decrease the subjective judgement in the implementation of information classification in organisations, which can lead to information security breaches because the information is under- or over-classified. Design/methodology/approach: The results are based on a design science research approach, implemented as five iterations spanning the years 2013 to 2019. Findings: The paper presents a method for information classification and the design principles underpinning the method. The empirical demonstration shows that senior and novice information security managers perceive the method as a useful tool for classifying information assets in an organisation. Research limitations/implications: Existing research has, to a limited extent, provided extensive advice on how to approach information classification in organisations systematically. The method presented in this paper can act as a starting point for further research in this area, aiming at decreasing subjectivity in the information classification process. Additional research is needed to fully validate the proposed method for information classification and its potential to reduce the subjective judgement. Practical implications: The research contributes to practice by offering a method for information classification. It provides a hands-on-tool for how to implement an information classification process. Besides, this research proves that it is possible to devise a method to support information classification. This is important, because, even if an organisation chooses not to adopt the proposed method, the very fact that this method has proved useful should encourage any similar endeavour. Originality/value: The proposed method offers a detailed and well-elaborated tool for information classification. The method is generic and adaptable, depending on organisational needs.

Ämnesord

NATURVETENSKAP  -- Data- och informationsvetenskap -- Systemvetenskap, informationssystem och informatik (hsv//swe)
NATURAL SCIENCES  -- Computer and Information Sciences -- Information Systems (hsv//eng)
SAMHÄLLSVETENSKAP  -- Medie- och kommunikationsvetenskap -- Systemvetenskap, informationssystem och informatik med samhällsvetenskaplig inriktning (hsv//swe)
SOCIAL SCIENCES  -- Media and Communications -- Information Systems, Social aspects (hsv//eng)
NATURVETENSKAP  -- Data- och informationsvetenskap -- Datavetenskap (hsv//swe)
NATURAL SCIENCES  -- Computer and Information Sciences -- Computer Sciences (hsv//eng)

Nyckelord

Information classification
Information classification method
Information security management
Information security management systems
ISO Standards
Security of data
Design Principles
Design-science researches
Design/methodology/approach
Information assets
Long-term goals
Organisational
Subjective judgement
Classification (of information)
Information Systems
Informationssystem (IS)
Informatics

Publikations- och innehållstyp

ref (ämneskategori)
art (ämneskategori)

Till lärosätets databas

Kungliga biblioteket hanterar dina personuppgifter i enlighet med EU:s dataskyddsförordning (2018), GDPR. Läs mer om hur det funkar här.
Så här hanterar KB dina uppgifter vid användning av denna tjänst.

 
pil uppåt Stäng

Kopiera och spara länken för att återkomma till aktuell vy