Information security risk management tools in the air traffic management domain: what are practitioners’ needs?Show others and affiliations
2025 (English)In: Information Security Journal, ISSN 1939-3555, E-ISSN 1939-3547, Vol. 34, no 6, p. 561-578Article in journal (Refereed) Published
Abstract [en]
Information Security Risk Management (ISRM) activities are essential for organizations seeking to control and monitor risk. However, it is well known that doing so is difficult, and the different ISRM activities provide different challenges. To provide support, ISRM tools can be used. Such tools can come in the form of spreadsheets, document templates, or dedicated software to support either part of or the full ISRM work. Few studies have been conducted investigating the use of such tools and their necessary properties. Through semi-structured interviews with 17 security practitioners in the Air Traffic Management (ATM) domain and five validation sessions with 34 experts, this study examines the needs of security practitioners using ISRM tools. The ATM domain was chosen as the study context since they use a method built on the ISO/IEC 27005 standard, which, unlike other ISRM frameworks, does not provide tool support. The findings contain a collection of properties needed in ISRM tools. Notably, the ability to get a holistic view of risks in and toward the organization, tool flexibility, and the ability to get assistance with documentation and information exchange. We also identify that current ISRM tools do not provide enough support and suggest ways to address this.
Place, publisher, year, edition, pages
Taylor & Francis, 2025. Vol. 34, no 6, p. 561-578
Keywords [en]
Air traffic management, aviation, cybersecurity, information security risk management, security practitioner
National Category
Information Systems, Social aspects
Identifiers
URN: urn:nbn:se:hj:diva-67705DOI: 10.1080/19393555.2025.2498472ISI: 001482570800001Scopus ID: 2-s2.0-105004473907Local ID: HOA;intsam;67705OAI: oai:DiVA.org:hj-67705DiVA, id: diva2:1956776
Funder
Interreg, 20357977Swedish Civil Contingencies Agency, 2021-14650EU, Horizon 2020, 7317652025-05-072025-05-072025-12-15Bibliographically approved