Change search
Link to record
Permanent link

Direct link
Kowalski, Stewart
Publications (10 of 37) Show all publications
Wahlgren, G. & Kowalski, S. (2019). A Maturity Model for IT-related Security Incident Management. In: Witold Abramowicz, Rafael Corchuelo (Ed.), Business Information Systems: Proceedings, Part I. Paper presented at 22nd International Conference, BIS 2019 Seville, Spain, June 26-28, 2019 (pp. 203-217). Springer
Open this publication in new window or tab >>A Maturity Model for IT-related Security Incident Management
2019 (English)In: Business Information Systems: Proceedings, Part I / [ed] Witold Abramowicz, Rafael Corchuelo, Springer, 2019, p. 203-217Conference paper, Published paper (Refereed)
Abstract [en]

The purpose of the study is to validate the ability of a maturity model for measuring escalation capability of IT-related security incident. First, an Escalation Maturity Model (EMM) and a tool were developed to measure the maturity of an organization to escalate IT-related security incidents. An IT tool for self-assessment was used by a representative from three organizations in the Swedish health sector to measure the organization’s ability to escalate IT-related security incident. Second, typical security incident scenarios were created. The incident managers from the different organizations were interviewed about their organization’s capabilities to deal with these scenarios. Third, a number of independent information security experts, none of whom had seen the results of EMM, ranked how the three different organizations have handled the different scenarios using a measurable scale. Finally, the results of EMM are compared against the measurable result of the interviews to establish the predictive ability of EMM. The findings of the proof of concept study shows that the outcome of EMM and the way in which an organization would handle different incidents correspond well, at least for organizations with low and medium maturity levels.

Place, publisher, year, edition, pages
Springer, 2019
Series
Lecture Notes in Business Information Processing, ISSN 1865-1348, E-ISSN 1865-1356 ; 353
Keywords
Incident escalation, Incident management, Maturity models, Self-assessment.
National Category
Information Systems
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-177127 (URN)10.1007/978-3-030-20485-3_16 (DOI)000490868600016 ()978-3-030-20484-6 (ISBN)978-3-030-20485-3 (ISBN)
Conference
22nd International Conference, BIS 2019 Seville, Spain, June 26-28, 2019
Available from: 2019-12-17 Created: 2019-12-17 Last updated: 2022-02-26Bibliographically approved
Kowalski, S., Bednar, P., Nolte, A. & Bider, I. (Eds.). (2019). STPIS 2019: Socio-Technical Perspective in IS Development 2019: Proceedings. Paper presented at 5th International Workshop on Socio-Technical Perspective in IS Development (STPIS 2019) co-located with 27th European Conference on Information Systems (ECIS 2019), Stockholm, Sweden, June 10, 2019. Technical University of Aachen
Open this publication in new window or tab >>STPIS 2019: Socio-Technical Perspective in IS Development 2019: Proceedings
2019 (English)Conference proceedings (editor) (Refereed)
Abstract [en]

This volume contains the papers presented at STPIS'19: 5th International Workshop on Socio-Technical Perspective in IS Development was held on June 10, 2019 in Stockholm, Sweden.

Place, publisher, year, edition, pages
Technical University of Aachen, 2019. p. 170
Series
CEUR Workshop Proceedings, E-ISSN 1613-0073 ; 2398
National Category
Information Systems
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-177182 (URN)
Conference
5th International Workshop on Socio-Technical Perspective in IS Development (STPIS 2019) co-located with 27th European Conference on Information Systems (ECIS 2019), Stockholm, Sweden, June 10, 2019
Available from: 2019-12-17 Created: 2019-12-17 Last updated: 2022-02-26Bibliographically approved
Wahlgren, G. & Kowalski, S. (2018). IT Security Risk Management Model for Handling IT-Related Security Incidents: The Need for a New Escalation Approach. In: Security and Privacy Management, Techniques, and Protocols: (pp. 129-151). IGI Global
Open this publication in new window or tab >>IT Security Risk Management Model for Handling IT-Related Security Incidents: The Need for a New Escalation Approach
2018 (English)In: Security and Privacy Management, Techniques, and Protocols, IGI Global, 2018, p. 129-151Chapter in book (Refereed)
Abstract [en]

Managing IT-related security incidents is an important issue facing many organizations in Sweden and around the world. To deal with this growing problem, the authors have used a design science approach to develop an artifact to measure different organizations' capabilities and maturity to handle IT-related security incidents. In this chapter, an escalation maturity model (artifact) is presented, which has been tested on several different Swedish organizations. The participating organizations come from both the private and public sectors, and all organizations handle critical infrastructure, which can be damaged if an IT-related security incident occurs. Organizations had the opportunity to evaluate the actual model itself and also to test the model by calculating the organization's escalation capability using a query package for self-assessment.

Place, publisher, year, edition, pages
IGI Global, 2018
Series
Advances in information security, privacy, and ethics book series, ISSN 1948-9730, E-ISSN 1948-9749
Keywords
Incident Escalation, Incident Management, Maturity Levels, Maturity Attribute, Maturity Models, Risk Communication, Risk Monitoring, Risk Treatment, Cloud Computing, Self-Assessment
National Category
Information Systems
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-164363 (URN)10.4018/978-1-5225-5583-4.ch005 (DOI)9781522555834 (ISBN)9781522555841 (ISBN)
Available from: 2019-01-15 Created: 2019-01-15 Last updated: 2023-07-22Bibliographically approved
Kowalski, S., Bednar, P. & Bider, I. (2018). Proceedings of STPIS'18: Preface. In: Stewart Kowalski, Peter Bednar, Ilia Bider (Ed.), 4th International Workshop on Socio-Technical Perspective in IS development (STPIS'18): Proceedings. Paper presented at 4th Workshop on Socio-Technical Perspective in IS development (STPIS'18), Tallinn, Estonia, June 12, 2018 (pp. i-iii). CEUR-WS.org
Open this publication in new window or tab >>Proceedings of STPIS'18: Preface
2018 (English)In: 4th International Workshop on Socio-Technical Perspective in IS development (STPIS'18): Proceedings / [ed] Stewart Kowalski, Peter Bednar, Ilia Bider, CEUR-WS.org , 2018, p. i-iiiConference paper, Published paper (Other academic)
Abstract [en]

This volume contains the papers presented at STPIS'18: 4th International Workshop on Socio-Technical Perspective in IS Development to beheld on June 12, 2018 in Tallinn, Estonia.

Place, publisher, year, edition, pages
CEUR-WS.org, 2018
Series
CEUR Workshop Proceedings, E-ISSN 1613-0073 ; 2107
National Category
Information Systems
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-163214 (URN)
Conference
4th Workshop on Socio-Technical Perspective in IS development (STPIS'18), Tallinn, Estonia, June 12, 2018
Available from: 2018-12-18 Created: 2018-12-18 Last updated: 2022-02-16Bibliographically approved
Kowalski, S., Bednar, P. & Bider, I. (Eds.). (2018). STPIS 2018 Socio-Technical Perspective in IS Development: Proceedings of the 4th International Workshop on Socio-Technical Perspective in IS Development co-located with 30th International Conference on Advanced Information Systems Engineering (CAiSE 2018). Paper presented at 4th International Workshop on Socio-Technical Perspective in IS development (STPIS'18)co-located with 30th International Conference on Advanced Information Systems Engineering (CAiSE 2018), Tallinn, Estonia, June 12, 2018. CEUR-WS.org
Open this publication in new window or tab >>STPIS 2018 Socio-Technical Perspective in IS Development: Proceedings of the 4th International Workshop on Socio-Technical Perspective in IS Development co-located with 30th International Conference on Advanced Information Systems Engineering (CAiSE 2018)
2018 (English)Conference proceedings (editor) (Refereed)
Place, publisher, year, edition, pages
CEUR-WS.org, 2018. p. 129
Series
CEUR Workshop Proceedings, E-ISSN 1613-0073 ; 2107
National Category
Information Systems
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-178746 (URN)
Conference
4th International Workshop on Socio-Technical Perspective in IS development (STPIS'18)co-located with 30th International Conference on Advanced Information Systems Engineering (CAiSE 2018), Tallinn, Estonia, June 12, 2018
Available from: 2020-02-03 Created: 2020-02-03 Last updated: 2022-02-26Bibliographically approved
Kowalski, S., Bednar, P. & Bider, I. (2017). Proceedings of STPIS’17: Preface. In: Stewart Kowalski, Peter Bednar, Ilia Bider (Ed.), Proceedings of the 3rd International Workshop on Socio-Technical Perspective in IS development (STPIS'17): . Paper presented at 3rd International Workshop on Socio-Technical Perspective in IS development (STPIS'17) co-located with 29th International Conference on Advanced Information Systems Engineering (CAiSE 2017), Essen, Germany, June 13, 2017 (pp. i-ii). CEUR-WS.org
Open this publication in new window or tab >>Proceedings of STPIS’17: Preface
2017 (English)In: Proceedings of the 3rd International Workshop on Socio-Technical Perspective in IS development (STPIS'17) / [ed] Stewart Kowalski, Peter Bednar, Ilia Bider, CEUR-WS.org , 2017, p. i-iiConference paper, Published paper (Other academic)
Place, publisher, year, edition, pages
CEUR-WS.org, 2017
Series
CEUR Workshop Proceedings, E-ISSN 1613-0073 ; 1854
National Category
Information Systems
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-149434 (URN)
Conference
3rd International Workshop on Socio-Technical Perspective in IS development (STPIS'17) co-located with 29th International Conference on Advanced Information Systems Engineering (CAiSE 2017), Essen, Germany, June 13, 2017
Available from: 2017-11-30 Created: 2017-11-30 Last updated: 2023-07-22Bibliographically approved
Al Sabbagh, B. & Kowalski, S. (2017). Socio-Technical SIEM (ST-SIEM): Towards Bridging the Gap in Security Incident Response. International Journal of Systems and Society, 4(2), 8-21, Article ID 2.
Open this publication in new window or tab >>Socio-Technical SIEM (ST-SIEM): Towards Bridging the Gap in Security Incident Response
2017 (English)In: International Journal of Systems and Society, ISSN 2327-3984, Vol. 4, no 2, p. 8-21, article id 2Article in journal (Refereed) Published
Abstract [en]

This article discusses the design and specifications of a Socio-Technical Security Information and Event Management System (ST-SIEM). This newly-developed artifact addresses an important limitation identified in today incident response practice—the lack of sufficient context in actionable security information disseminated to constituent organizations. ST-SIEM tackles this limitation by considering the socio-technical aspect of information systems security. This concept is achieved by correlating the technical metrics of security warnings (which are generic in nature, and the sources of which are sometimes unknown) with predefined social security metrics (used for modeling the security culture of constituent organizations). ST-SIEM, accordingly, adapts the risk factor of the triggered security warning based on each constituent organization security culture. Moreover, the artifact features several socio-technical taxonomies with an impact factor to support organizations in classifying, reporting, and escalating actionable security information. The overall project uses design science research as a framework to develop the artifact.

Keywords
socio-technical, Security Information and Event Management System, SIEM, ST-SIEM, taxonomies, information systems security, incident response
National Category
Information Systems, Social aspects
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-149438 (URN)10.4018/IJSS.2017070102 (DOI)
Available from: 2017-11-30 Created: 2017-11-30 Last updated: 2023-07-22Bibliographically approved
Al Sabbagh, B. & Kowalski, S. (2016). A Framework and Prototype for A Socio-Technical Security Information and Event Management System (ST-SIEM). In: Joel Brynielsson, Fredrik Johansson (Ed.), 2016 European Intelligence and Security Informatics Conference: Proceedings. Paper presented at 2016 European Intelligence and Security Informatics Conference, Uppsala, Sweden, 17–19 August 2016 (pp. 192-195). IEEE Computer Society
Open this publication in new window or tab >>A Framework and Prototype for A Socio-Technical Security Information and Event Management System (ST-SIEM)
2016 (English)In: 2016 European Intelligence and Security Informatics Conference: Proceedings / [ed] Joel Brynielsson, Fredrik Johansson, IEEE Computer Society, 2016, p. 192-195Conference paper, Published paper (Refereed)
Abstract [en]

In this short paper we present a socio-technical framework for integrating a security risk escalation maturity model into a security information and event management system. The objective of the framework is to develop the foundations for the next generation socio-technical security information and event management systems (ST-SIEMs) enabling socio-technical security operations centers (ST-SOCs). The primary benefit of the socio-technical framework is twofold: supporting organizations in overcoming the identified limitations in their security risk escalation maturity, and supporting SOCs in overcoming the limitations of their SIEMs. The risk escalation maturity level is quantified using metrics. These metrics are then used by SIEMs for cross correlating security events before they are disseminated to respective organizations. Typical SIEMs in use today calculate security events using generic risk factors not necessarily relevant for every organization. The proposed framework can enable security administrators to effectively and efficiently manage security warnings and to establish necessary countermeasures.

Place, publisher, year, edition, pages
IEEE Computer Society, 2016
Keywords
SIEM, Socio-Technical SIEM, SOC, Risk Escalation
National Category
Information Systems, Social aspects
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-153268 (URN)10.1109/EISIC.2016.049 (DOI)978-1-5090-2857-3 (ISBN)
Conference
2016 European Intelligence and Security Informatics Conference, Uppsala, Sweden, 17–19 August 2016
Available from: 2018-02-23 Created: 2018-02-23 Last updated: 2022-02-28Bibliographically approved
Wahlgren, G. & Kowalski, S. (2016). A Maturity Model for Measuring Organizations Escalation Capability of IT-related Security Incidents in Sweden. In: Workshop on Information Security and Privacy (WISP) 2016: Proceedings. Paper presented at WISP 2016, Dublin, Ireland, December 10, 2016. Association for Information Systems, 8
Open this publication in new window or tab >>A Maturity Model for Measuring Organizations Escalation Capability of IT-related Security Incidents in Sweden
2016 (English)In: Workshop on Information Security and Privacy (WISP) 2016: Proceedings, Association for Information Systems, 2016, Vol. 8Conference paper, Published paper (Refereed)
Abstract [en]

Managing IT-related security incidents are a growing important issue facing the organizations in IT security risk management. We have used design science approach to develop an artifact to measure different organizations capabilities and maturity to handle IT-related security incidents. In this paper, we present how we have tested and will test the artifact on several different Swedish organizations. The participating organizations come from both the private and public sectors and all organizations handle critical infrastructure which can be damaged if an IT-related security incident occurs. Organizations had the opportunity to evaluating the actual model itself but also to test the model by calculating the organization's escalation capability using a query package for self-assessment. In this paper, we present the results of the self-assessment which indicate an overall low level of maturity in Sweden. The most remarkable result was only 20% of the participating organizations in the study had "Knowledge and Education" maturity above the lowest levels.

Place, publisher, year, edition, pages
Association for Information Systems, 2016
Keywords
Incident escalation, Maturity models, IT security risk management, Incident management.
National Category
Information Systems
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-144914 (URN)
Conference
WISP 2016, Dublin, Ireland, December 10, 2016
Available from: 2017-06-29 Created: 2017-06-29 Last updated: 2022-02-28Bibliographically approved
Wahlgren, G., Fedotova, A., Musaeva, A. & Kowalski, S. (2016). IT Security Incidents Escalation in the Swedish financial sector: A Maturity Model Study. In: Nathan L. Clarke, Steven M. Furnell (Ed.), Proceedings of the Tenth International Symposium on Human Aspects of Information Security & Assurance (HAISA 2016): . Paper presented at Tenth International Symposium on Human Aspects of Information Security & Assurance (HAISA 2016) Frankfurt, Germany, July 19-21, 2016 (pp. 45-55). Plymouth University
Open this publication in new window or tab >>IT Security Incidents Escalation in the Swedish financial sector: A Maturity Model Study
2016 (English)In: Proceedings of the Tenth International Symposium on Human Aspects of Information Security & Assurance (HAISA 2016) / [ed] Nathan L. Clarke, Steven M. Furnell, Plymouth University , 2016, p. 45-55Conference paper, Published paper (Refereed)
Abstract [en]

This paper reports the primary results of a design science research study to deal with the problem of IT security escalation in Swedish government and private organizations. A maturity capability escalation model was used to perform evaluations of two of Sweden's four largest banks. The evaluation indicated that banks were aligned with the current Swedish regulations minimal requirements for IT security incident handling and where on a level 3 of a 5 level model.

Place, publisher, year, edition, pages
Plymouth University, 2016
Keywords
Incident Escalation, Maturity Models, IT Security Risk Management, Financial Sector
National Category
Information Systems
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-135431 (URN)978-1-84102-413-4 (ISBN)
Conference
Tenth International Symposium on Human Aspects of Information Security & Assurance (HAISA 2016) Frankfurt, Germany, July 19-21, 2016
Available from: 2016-11-08 Created: 2016-11-08 Last updated: 2022-02-28Bibliographically approved
Organisations

Search in DiVA

Show all publications