Abstract
This paper presents a case study on current practice of information security incident management in three large organizations.
Qualitative interviews, document studies, and a survey have been performed. Our analysis shows that the organizations have
plans and procedures in place, however, not all of these are well established throughout the organizations. Some challenges were
prominent in all three organizations, which were related to communication, information collection and dissemination, employee
involvement, and allocation of responsibilities. This paper presents our main findings from the study, including current practice
for incident management and more details on the identified challenges, and some recommendations for further studies in this field.
Qualitative interviews, document studies, and a survey have been performed. Our analysis shows that the organizations have
plans and procedures in place, however, not all of these are well established throughout the organizations. Some challenges were
prominent in all three organizations, which were related to communication, information collection and dissemination, employee
involvement, and allocation of responsibilities. This paper presents our main findings from the study, including current practice
for incident management and more details on the identified challenges, and some recommendations for further studies in this field.