Redefining information systems security: viable information systems

  • Authors:
  • Maria Karyda;Spyros Kokolakis;Evangelos Kiountouzis

  • Affiliations:
  • Athens Univ. of Economics and Business, Athens, Greece;Univ. of the Aegean, Greece;Athens Univ. of Economics and Business, Athens, Greece

  • Venue:
  • Sec '01 Proceedings of the 16th international conference on Information security: Trusted information: the new decade challenge
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

Research on Information Security has been based on a well-established definition of the subject. Consequently, it has delivered a plethora of methods, techniques, mechanisms and tools to protect the so-called security attributes (i.e. availability, confidentiality and integrity) of information. However, a modern Information System (IS) appear rather vulnerable and people show mistrust on their ability to deliver the services expected. This phenomenon leads us to the conclusion that information security does not necessarily equal IS security. In this paper, we argue that IS security, contrary to information remains a confusing term and a neglected research area. We attempt to clarify the meaning and aims of IS security and propose a framework for building secure information systems, or as we suggest them to be called, viable information systems.