Organizational Cybersecurity Journal editorial introduction

Gurvirender P. S. Tejay, Gary Klein · Organizational Cybersecurity Journal Practice Process and People · 2021

Technical cybersecurity dominates discussion and investment even though there is a realization to approach cybersecurity problems from organizational cybersecurity or information security management perspectives.The technical focus is further reflected in the predominance of technical education programs and even "Capture-the-flag" competitions.Yet, calls to focus on the management aspects of protecting information assets or considering the business risks can be traced back over half a century.In an article entitled "Danger Ahead!Safeguard Your Computer," the author raises ". . .serious questions about security for the management to consider: Could the company continue to transact its business if its computer center and everything in it were suddenly destroyed?Has the company properly protected its programs, files, and equipment against sabotage?"(Allen, 1968, p. 97).The author further notes (p.101):Although perfect security systems, as always, are beyond reach, a company can implement a very satisfactory one at reasonable cost.What is needed most right now is management's awareness of the problem, an appreciation of the hazards involved and a determination to prevent severe misfortunes.Shortly after that warning, Sorensen (1972) opened an article with words that continue to resonate and are reflected in everyday news stories (p.379): Suddenly, everyone's concerned about computer security . . .New Companies have been formed specializing in products that provide better security in a computer department; and seminars are being offered around the country dealing with control and security of computer installations.Management is concerned.It has realized that its computer department, the heart of its day-to-day vital information and control system, has unique vulnerability to theft, disruption and destruction.Our chosen area of cybersecurity management is still considered to be a nascent field and needs nurturing.Cybersecurity impacts not only the technical side of an organization but also brand image, ethical and legal obligations, continuing operations, customer relations, internal processes, risk management, system audits, strategic initiatives and almost every dimension of sustaining and growing a successful organization.We collectively have a shared responsibility to get actively involved and mold it towards a mature management discipline.Of the many journals that publish cyber and computer security research, most focus on technology, systems, crime and data protection.Those that consider organizational issues cover a very broad scope and do not zero in on the aspects that impact organizations.Organizational Cybersecurity Journal: Practice, Process, and People (OCJ) seeks to publish advances in scientific knowledge directly related to cybersecurity management.We target research relating to the behaviors and practices that influence the successful management of cybersecurity.The journal welcomes papers from human, technical and process perspectives on the topic.We endeavor to establish this journal as a prominent journal in the emerging discipline of cybersecurity.

Read the paper · More papers on PaperTik