Have a personal or library account? Click to login
Outsource or not? An AHP Based Decision Model for Information Security Management Cover

Outsource or not? An AHP Based Decision Model for Information Security Management

Open Access
|Jun 2022

Abstract

Purpose: Outsourcing information security has proven to be an efficient solution for information security management; however, it may not be the most suitable approach for every organization. This research aimed to develop a multi-criteria decision-making model that would enable organizations to determine which approach to information security management (outsourcing or internal management) is more suitable for their needs and capabilities.

Methods: Our study utilized several different research methods. First, the decision criteria were identified by reviewing related work and then selected by information security experts in a focus group. Second, a survey was conducted among information security practitioners to assign the criteria weights. Third, four use cases were conducted with four real-world organizations to assess the usability, ease of use, and usefulness of the developed model.

Results: We developed a ten-criteria model based on the analytic hierarchy process. The survey results promote performance-related criteria as more important than efficiency-focused criteria. Evidence from use cases proves that the decision model is useful and appropriate for various organizations.

Conclusion: To make informed decisions on approaching information security management, organizations must first conduct a thorough analysis of their capabilities and needs and investigate potential external contractors. In such a case, the proposed model can serve as a useful support tool in the decision-making process to obtain clear recommendations tailored to factual circumstances.

DOI: https://doi.org/10.2478/orga-2022-0010 | Journal eISSN: 1581-1832 | Journal ISSN: 1318-5454
Language: English
Page range: 142 - 159
Submitted on: Nov 3, 2021
Accepted on: Apr 28, 2022
Published on: Jun 23, 2022
Published by: Sciendo
In partnership with: Paradigm Publishing Services
Publication frequency: 4 times per year

© 2022 Luka Jelovčan, Anže Mihelič, Kaja Prislan, published by Sciendo
This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 License.