Abstract When taking a typical approach to computer security, one could make the following relatively extreme statements: A piece of data can be rendered completely secure with 100 percent assurance. Simply write the data on a piece of paper, burn the paper, and scatter the ashes. No one will be able to read or alter that data ever again. Of course, this exercise and the underlying premise are a trick. Understanding the deception is the key to understanding information security: Data that is being “protected” has to remain available to legitimate users. There is a strong tendency for information security researchers and practitioners to focus on “securing” data by preventing attacks and loss of data. An IS practitioner's job might depend on preventing and recovering from security-related problems. However, increased monitoring and enhanced use of security controls can easily lead to interference and delays of information usage for legitimate users.
[1]
Gerald V. Post.
Improving operating system security
,
1987,
Comput. Secur..
[2]
Theodore Tryfonas,et al.
From risk analysis to effective security management: towards an automated approach
,
2004,
Inf. Manag. Comput. Secur..
[3]
Carl E. Landwehr,et al.
Computer security
,
2001,
International Journal of Information Security.
[4]
Butler W. Lampson,et al.
31. Paper: Computer Security in the Real World Computer Security in the Real World
,
2022
.
[5]
Gerald V. Post,et al.
Accessibility vs. security: A look at the demand for computer security
,
1991,
Comput. Secur..
[6]
RICHAFID BASKERVILLE,et al.
Information systems security design methods: implications for information systems development
,
1993,
CSUR.