{"id":"https://openalex.org/W4398234340","doi":"https://doi.org/10.1145/3658321.3658363","title":"Information Security Investments: How to Prioritize?","display_name":"Information Security Investments: How to Prioritize?","publication_year":2024,"publication_date":"2024-05-20","ids":{"openalex":"https://openalex.org/W4398234340","doi":"https://doi.org/10.1145/3658321.3658363"},"language":"en","primary_location":{"id":"doi:10.1145/3658321.3658363","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3658321.3658363","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 20th Brazilian Symposium on Information Systems","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5102810622","display_name":"Mariana Batista Oliveira","orcid":"https://orcid.org/0000-0001-6313-6755"},"institutions":[{"id":"https://openalex.org/I4210142765","display_name":"Instituto de Pesquisas Tecnol\u00f3gicas","ror":"https://ror.org/041mvdf76","country_code":"BR","type":"facility","lineage":["https://openalex.org/I4210142765"]}],"countries":["BR"],"is_corresponding":false,"raw_author_name":"Mariana Batista Oliveira","raw_affiliation_strings":["Instituto de Pesquisas Tecnol\u00f3gicas - IPT, Brazil"],"raw_orcid":"https://orcid.org/0000-0001-6313-6755","affiliations":[{"raw_affiliation_string":"Instituto de Pesquisas Tecnol\u00f3gicas - IPT, Brazil","institution_ids":["https://openalex.org/I4210142765"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5005500028","display_name":"Alfredo Goldman","orcid":"https://orcid.org/0000-0001-5746-4154"},"institutions":[{"id":"https://openalex.org/I17974374","display_name":"Universidade de S\u00e3o Paulo","ror":"https://ror.org/036rp1748","country_code":"BR","type":"education","lineage":["https://openalex.org/I17974374"]}],"countries":["BR"],"is_corresponding":false,"raw_author_name":"Alfredo Goldman","raw_affiliation_strings":["Universidade de S\u00e3o Paulo, Brazil"],"raw_orcid":"https://orcid.org/0000-0001-5746-4154","affiliations":[{"raw_affiliation_string":"Universidade de S\u00e3o Paulo, Brazil","institution_ids":["https://openalex.org/I17974374"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5081439231","display_name":"Joseph W. Yoder","orcid":"https://orcid.org/0009-0006-9157-0050"},"institutions":[{"id":"https://openalex.org/I17974374","display_name":"Universidade de S\u00e3o Paulo","ror":"https://ror.org/036rp1748","country_code":"BR","type":"education","lineage":["https://openalex.org/I17974374"]}],"countries":["BR"],"is_corresponding":false,"raw_author_name":"Joseph Yoder","raw_affiliation_strings":["Universidade de S\u00e3o Paulo, Brazil"],"raw_orcid":"https://orcid.org/0009-0006-9157-0050","affiliations":[{"raw_affiliation_string":"Universidade de S\u00e3o Paulo, Brazil","institution_ids":["https://openalex.org/I17974374"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.6895,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.73504491,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9955999851226807,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12519","display_name":"Cybercrime and Law Enforcement Studies","score":0.9932000041007996,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/information-security","display_name":"Information security","score":0.6061751842498779},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5876015424728394},{"id":"https://openalex.org/keywords/information-security-management","display_name":"Information security management","score":0.4618225693702698},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4422527849674225},{"id":"https://openalex.org/keywords/security-information-and-event-management","display_name":"Security information and event management","score":0.30301713943481445},{"id":"https://openalex.org/keywords/cloud-computing-security","display_name":"Cloud computing security","score":0.22899529337882996},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.07672417163848877}],"concepts":[{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.6061751842498779},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5876015424728394},{"id":"https://openalex.org/C148976360","wikidata":"https://www.wikidata.org/wiki/Q1662500","display_name":"Information security management","level":5,"score":0.4618225693702698},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4422527849674225},{"id":"https://openalex.org/C103377522","wikidata":"https://www.wikidata.org/wiki/Q3493999","display_name":"Security information and event management","level":4,"score":0.30301713943481445},{"id":"https://openalex.org/C184842701","wikidata":"https://www.wikidata.org/wiki/Q370563","display_name":"Cloud computing security","level":3,"score":0.22899529337882996},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.07672417163848877},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3658321.3658363","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3658321.3658363","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 20th Brazilian Symposium on Information Systems","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/8","display_name":"Decent work and economic growth","score":0.47999998927116394}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":16,"referenced_works":["https://openalex.org/W2113700906","https://openalex.org/W2738072326","https://openalex.org/W2772274819","https://openalex.org/W2914630228","https://openalex.org/W2985776815","https://openalex.org/W3028313011","https://openalex.org/W3033915435","https://openalex.org/W3134382644","https://openalex.org/W3159979075","https://openalex.org/W3186595770","https://openalex.org/W4200188692","https://openalex.org/W4210570127","https://openalex.org/W4224218656","https://openalex.org/W4234251954","https://openalex.org/W4236255155","https://openalex.org/W4255820203"],"related_works":["https://openalex.org/W2120971814","https://openalex.org/W2508914475","https://openalex.org/W4310892428","https://openalex.org/W4293770853","https://openalex.org/W2356973015","https://openalex.org/W2777401565","https://openalex.org/W2248314326","https://openalex.org/W4390655704","https://openalex.org/W2033357182","https://openalex.org/W4299810435"],"abstract_inverted_index":{"Context:":[0],"In":[1,106,210],"an":[2],"increasingly":[3],"digitalized":[4],"world":[5],"with":[6,38,41,293],"more":[7],"complex":[8],"supply":[9],"chains,":[10],"there":[11,198],"is":[12,161,185,199,207],"concern":[13],"about":[14,203],"the":[15,22,35,72,100,128,135,152,171,178,205,242,252,257,275,284,287,291,294],"security":[16,102,125,222,261,313],"of":[17,48,74,81,95,130,259,279,283,297,303,308],"sharing":[18,39],"information.":[19],"To":[20],"highlight":[21],"associated":[23,37],"risk,":[24],"companies":[25,132,229,254],"carry":[26],"out":[27,218],"Information":[28,59],"Security":[29,60],"Risk":[30,61],"Assessments":[31],"(ISRAs),":[32],"to":[33,71,112,120,133,151,170,193,230,240,269],"measure":[34],"risk":[36,49,223],"information":[40,101,124,148,221,260,312],"a":[42,55,78,122,213,231],"third":[43],"party.":[44],"There":[45],"are":[46,52,69,90,168,256],"dozens":[47],"frameworks":[50,190],"that":[51,83,89,117,163],"used":[53,239],"as":[54],"basis":[56],"for":[57,145,251],"creating":[58],"Assessment":[62],"forms.":[63],"These":[64],"forms,":[65],"in":[66,99,147,154,286,306,311],"most":[67,118,175,243,248],"cases,":[68],"adapted":[70],"reality":[73],"each":[75],"company,":[76],"generating":[77],"large":[79],"number":[80,296],"questions":[82],"can":[84],"be":[85],"asked":[86],"or":[87,127,191],"topics":[88,250],"priorities.":[91],"This":[92],"wide":[93],"range":[94],"possibilities":[96],"generates":[97],"inefficiencies":[98],"supplier":[103,309],"management":[104,310],"process.":[105],"addition,":[107],"this":[108,183,211,304],"makes":[109],"it":[110,160],"difficult":[111],"prioritize":[113],"efforts":[114],"on":[115,182,187,219],"topics,":[116],"contribute":[119],"increasing":[121],"company\u2019s":[123],"maturity":[126,302],"suitability":[129],"these":[131],"what":[134,204],"market":[136,158,206],"demands.":[137],"Problem:":[138],"Companies":[139],"do":[140],"not":[141],"have":[142],"unlimited":[143],"resources":[144,167],"investments":[146],"security.":[149],"Due":[150],"increase":[153],"cybercrimes":[155],"and":[156,165,173,265,271,273,277],"consequently":[157],"demands,":[159],"important":[162],"human":[164],"financial":[166,288],"directed":[169],"themes":[172],"adjustments":[174],"required":[176],"by":[177,227],"market.":[179],"Current":[180],"research":[181,202],"topic":[184],"focused":[186],"comparing":[188],"risky":[189],"trying":[192],"improve":[194],"their":[195],"efficiency,":[196],"however,":[197],"very":[200],"little":[201],"demanding.":[208],"Method:":[209],"work,":[212],"qualitative":[214],"analysis":[215],"was":[216,238,290],"carried":[217],"5":[220,253],"assessment":[224],"forms":[225],"sent":[226],"multinational":[228],"Brazilian":[232],"healthcare":[233],"operator.":[234],"Atlas":[235],"TI":[236],"tool":[237],"identify":[241],"recurrent":[244],"themes.":[245],"Results:":[246],"The":[247,281],"relevant":[249],"evaluated":[255],"existence":[258],"policies,":[262],"incident":[263],"prevention":[264],"response":[266],"plans,":[267],"adaptation":[268],"legislation":[270],"compliance,":[272],"ensuring":[274],"protection":[276],"privacy":[278],"data.":[280],"ISRA":[282],"company":[285],"sector":[289,305],"one":[292],"highest":[295],"questions,":[298],"which":[299],"indicates":[300],"greater":[301],"terms":[307],"topics.":[314]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
