As information and communication technologies become a critical component of firms’ infrastructures and information establishes itself as a key business resource as well as driver, people start to realise that there is more than the functionality of the new information systems that is significant. Business or organisational transactions over new media require stability, one factor of which is information security. Information systems development practices have changed in line with the evolution of technology offerings as well as the nature of systems developed. Nevertheless, as this paper establishes, most contemporary development practices do not accommodate sufficiently security concerns. Beyond the literature evidence, reports on empirical study results indicating that practitioners deal with security issues by applying conventional risk analysis practices after the system is developed. Addresses the lack of a defined discipline for security concerns integration in systems development by using field study results recording development practices that are currently in use to illustrate their deficiencies, to point to required enhancements of practice and to propose a list of desired features that contemporary development practices should incorporate to address security concerns.
Article navigation
1 October 2001
This article was originally published in
Information Management & Computer Security
Technical Paper|
October 01 2001
Embedding security practices in contemporary information systems development approaches
T. Tryfonas;
T. Tryfonas
Department of Informatics, Athens University of Economics and Business, Athens, Greece
Search for other works by this author on:
E. Kiountouzis;
E. Kiountouzis
Department of Informatics, Athens University of Economics and Business, Athens, Greece
Search for other works by this author on:
A. Poulymenakou
A. Poulymenakou
Department of Informatics, Athens University of Economics and Business, Athens, Greece
Search for other works by this author on:
Publisher: Emerald Publishing
Online ISSN: 1758-5805
Print ISSN: 0968-5227
© MCB UP Limited
2001
Information Management & Computer Security (2001) 9 (4): 183–197.
Citation
Tryfonas T, Kiountouzis E, Poulymenakou A (2001), "Embedding security practices in contemporary information systems development approaches". Information Management & Computer Security, Vol. 9 No. 4 pp. 183–197, doi: https://doi.org/10.1108/09685220110401254
Download citation file:
468
Views
New and popular articles
Suggested Reading
JISC development
VINE (March,2002)
Interaction, transformation and information systems development – an extended application of Soft Systems Methodology
Information Technology & People (September,2002)
Y2K contingency planning workshops
Facilities (July,1999)
Information systems careers: the role of assessment centers
Career Development International (July,1998)
The successful development of information systems for FMS: some useful lessons
Industrial Management & Data Systems (December,1997)
Related Chapters
Chapter 6 Adaptive Economizing, Creativity, and Multiple-Phase Evolution
Economic Growth and Development
Challenges for Globalised Information Systems in a Multilingual and Multicultural Context
Library and Information Science Trends and Research: Europe
e-HRM Systems in Support of “Smart” Workforce Management: An Exploratory Case Study of System Success
Electronic HRM in the Smart Era
Recommended for you
These recommendations are informed by your reading behaviors and indicated interests.
