A framework for selection of strategy for management of security measures

In this paper, we present and discuss a framework for security risk management, focusing on the selection of a management strategy for decision-making on security measures in particular. The framework provides guidance on the selection of a suitable type of management strategy for various types of decision-making contexts. An Information and Communication Technology case study is used to illustrate the practical implications of the framework.