Abbas Shahim

dblp:18/3772 · DBLP profile ↗
← Back
5ranked-venue papers
1as first author
4since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 4 since 2021
YearPublicationVenuePosition
2024 Multi-method Approach to Human Expertise, Automation, and Artificial Intelligence for Vulnerability Management - Investigation of Challenges and Emerging Tensions
Mehdi Saadallah, Abbas Shahim, Svetlana Khapova
SEC2
2022 Paradoxical tensions in the implementation of digital security governance: Toward an ambidextrous approach to governing digital security
abstract
Due to increasing numbers of cyberattacks, security is one of the leading challenges to contemporary organizations. As contradictory demands (e.g., tensions in digital organizations) intensify, organizations increasingly find it difficult to implement digital security governance (DSG) as part of their regular organizational change activities. Based on data from forty-two interviews with Dutch CISOs and CIOs of large organizations that are active in various sectors, we identify three key paradoxical tensions that affect DSG implementation. We found that in a digital context, paradoxical tensions are pressurized and become out of balance. Disbalance among tensions exposes friction that hinders the implementation of DSG mechanisms. Finally, we present a conceptual model that sets direction for ambidextrous digital security. Understanding how to engage with tensions in an ambidextrous way determines the success of DSG implementations in today's complex digital environments.
Stef Schinagl, Abbas Shahim, Svetlana Khapova
Comput. Secur.2
2021 Tensions that Hinder the Implementation of Digital Security Governance
Stef Schinagl, Svetlana Khapova, Abbas Shahim
SEC3
2021 Security of the digital transformation
abstract
In the early days of computation the focus was mainly on designing, developing, maintaining, and administering infrastructures and information systems housed in data centers. To this extend, security was traditionally organized around the basic technical components (e.g. data center facilities). The point was that an associated security activity was mostly separated from a business context and in general executed by the technical staff. Security was not fully understood by other audiences because the computer terminologies were frequently used. When security elements (e.g. logical access protocols used for identification, authentication, authorization) became part of the financial statement audit, its context became clearer, and it was conducted for external auditors. However, the presented outcome of the work was not completely interpretable for these practitioners as again, it was mainly reported in Information Technology (IT) jargon, and was not linked with the financial statement either. With the emergence the Sarbanes–Oxley Act (SOX) and the fundamental role of IT in relation hereto, the context of security suddenly changed to a great extent. The audience extended as compliance, including security, became the dominating item on the agenda of many C-levels (e.g. CFOs).
Abbas Shahim
Comput. Secur.1
2020 What do we know about information security governance?
abstract
Purpose This paper aims to review the information security governance (ISG) literature and emphasises the tensions that exist at the intersection of the rapidly changing business climate and the current body of knowledge on ISG. Design/methodology/approach The intention of the authors was to conduct a systematic literature review. However, owing to limited empirical papers in ISG research, this paper is more conceptually organised. Findings This paper shows that security has shifted from a narrow-focused isolated issue towards a strategic business issue with “from the basement to the boardroom” implications. The key takeaway is that protecting the organisation is important, but organizations must also develop strategies to ensure resilient businesses to take advantage of the opportunities that digitalization can bring. Research limitations/implications The concept of DSG is a new research territory that addresses the limitations and gaps of traditional ISG approaches in a digital context. To this extent, organisational theories are suggested to help build knowledge that offers a deeper understanding than that provided by the too often used practical approaches in ISG research. Practical implications This paper supports practitioners and decision makers by providing a deeper understanding of how organisations and their security approaches are actually affected by digitalisation. Social implications This paper helps individuals to understand that they have increasing rights with regard to privacy and security and a say in what parties they assign business to. Originality/value This paper makes a novel contribution to ISG research. To the authors’ knowledge, this is the first attempt to review and structure the ISG literature.
Stef Schinagl, Abbas Shahim
Inf. Comput. Secur.2