Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Information security risk management tools in the air traffic management domain: what are practitioners’ needs?
Luleå University of Technology, Department of Computer Science, Electrical and Space Engineering, Digital Services and Systems.ORCID iD: 0000-0002-4057-9454
School of Engineering, Jönköping University, Jönköping, Sweden.
School of Informatics, University of Skövde, Skövde, Sweden.
SINTEF Digital, Trondheim, Norway.
Show others and affiliations
2025 (English)In: Information Security Journal, ISSN 1939-3555, E-ISSN 1939-3547, Vol. 34, no 6, p. 561-578Article in journal (Refereed) Published
Abstract [en]

Information Security Risk Management (ISRM) activities are essential for organizations seeking to control and monitor risk. However, it is well known that doing so is difficult, and the different ISRM activities provide different challenges. To provide support, ISRM tools can be used. Such tools can come in the form of spreadsheets, document templates, or dedicated software to support either part of or the full ISRM work. Few studies have been conducted investigating the use of such tools and their necessary properties. Through semi-structured interviews with 17 security practitioners in the Air Traffic Management (ATM) domain and five validation sessions with 34 experts, this study examines the needs of security practitioners using ISRM tools. The ATM domain was chosen as the study context since they use a method built on the ISO/IEC 27005 standard, which, unlike other ISRM frameworks, does not provide tool support. The findings contain a collection of properties needed in ISRM tools. Notably, the ability to get a holistic view of risks in and toward the organization, tool flexibility, and the ability to get assistance with documentation and information exchange. We also identify that current ISRM tools do not provide enough support and suggest ways to address this. 

Place, publisher, year, edition, pages
Taylor & Francis, 2025. Vol. 34, no 6, p. 561-578
Keywords [en]
Air traffic management, aviation, cybersecurity, information security risk management, security practitioner
National Category
Information Systems, Social aspects
Research subject
Information Systems
Identifiers
URN: urn:nbn:se:ltu:diva-112600DOI: 10.1080/19393555.2025.2498472ISI: 001482570800001Scopus ID: 2-s2.0-105004473907OAI: oai:DiVA.org:ltu-112600DiVA, id: diva2:1956724
Note

Validerad;2025;Nivå 1;2025-11-05 (u2);

Full text: CC BY license;

Funder: Swedish Civil Contingencies Agency (MSB), project VISKA (MSB 2021-14650); SESAR JU under the EU H2020 research and innovation program (grant agreement 731765); Interreg [20357977];

Available from: 2025-05-07 Created: 2025-05-07 Last updated: 2026-03-18Bibliographically approved
In thesis
1. Beyond Levels: Supporting Information Classification
Open this publication in new window or tab >>Beyond Levels: Supporting Information Classification
2026 (English)Doctoral thesis, comprehensive summary (Other academic)
Abstract [en]

Information is a critical asset for organisations, enabling business processes and planning at strategic, tactical, and operational levels. Given its importance, information must be protected against risk, typically through information security risk management. Effective protection, however, requires an understanding of what information is valuable and why. Information classification provides this foundation by assessing the value of information assets and determining their organisational importance. Although classification is addressed in standards and academic literature, it has received limited empirical attention. Existing guidance explains what classification aims to achieve but offers little insight into how it is conducted in practice or how organisational conditions influence the process across strategic, tactical, and operational levels. As a result, key aspects of classification work remain underexplored.

Against this background, the purpose of this thesis is to create knowledge about the relevance of information classification within the strategic, tactical, and operational levels of an organisational context. To fulfil this purpose, the thesis identifies organisational prerequisites that enable meaningful classification, challenges that hinder it, and ways to support the practice and documentation of classification. These prerequisites, challenges, and support categories are analysed using a multi-level planning framework.

The research is based on five peer-reviewed studies, four of which were conducted in Swedish public sector organisations and one of which was conducted in the air traffic management domain. The empirical material includes semi-structured interviews, document analysis, tool demonstrations, and expert validation.

The findings demonstrate that information classification should not be understood merely as an isolated operational workshop activity. Instead, it is a multi-level organisational process shaped by strategic direction, tactical preparation, and operational execution. By adapting and applying a multi-level planning framework to information classification, the thesis shows that challenges and prerequisites identified during classification often originate from insufficient strategic framing and limited tactical support. Furthermore, classification is shown to be inherently interpretive. Subjective judgment plays a central role in assessing the value of information assets. In contrast to prior research, which often frames subjectivity as a weakness to be minimised, this thesis reconceptualises subjectivity as a necessary and unavoidable component of meaningful classification decisions. Finally, two main avenues for supporting classification are identified: automation and assistance. Automation refers to automating mainly administrative parts of classification, while assistance refers to providing support to carry out the process. Building on the assistance perspective, the thesis addresses an underdeveloped aspect of existing methods by developing structured documentation support that enables workshop participants to capture contextual knowledge and decision rationale. 

Abstract [sv]

Information är en kritisk tillgång för organisationer som möjliggör verksamhetsprocesser samt planering på strategisk, taktisk och operativ nivå. Med hänsyn till dess betydelse måste information skyddas mot risk, vanligtvis genom informationssäkerhetsriskhantering. Ett effektivt skydd förutsätter dock en förståelse för vilken information som är värdefull och varför. Informationsklassning utgör denna grund genom att bedöma värdet av informationstillgångar och fastställa deras organisatoriska betydelse. Även om informationsklassning behandlas i såväl standarder som akademisk litteratur har området fått begränsad empirisk uppmärksamhet. Nuvarande vägledning beskriver vad informationsklassning syftar till att uppnå men ger begränsad insikt i hur det genomförs i praktiken eller hur organisatoriska förutsättningar påverkar processen på strategisk, taktisk och operativ nivå. Detta har lett till att viktiga aspekter av klassningsarbetet är otillräckligt utforskade.

Mot denna bakgrund är syftet med avhandlingen att skapa kunskap om informationsklassningens relevans inom strategiska, taktiska och operativa nivåer i en organisatorisk kontext. För att uppfylla detta syfte identifierar avhandlingen organisatoriska förutsättningar som möjliggör meningsfull informationsklassning, utmaningar som försvårar den samt stöd för genomförandet och dokumentationen av klassning. Dessa förutsättningar, utmaningar och stödformer analyseras med hjälp av ett flernivåbaserat planeringsramverk. 

Avhandlingen baseras på fem sakkunniggranskade och publicerade studier, varav fyra har genomförts i svensk offentlig sektor och en i flygtrafikledningsområdet. Det empiriska materialet består av semistrukturerade intervjuer, dokumentanalys, verktygsdemonstrationer och expertvalidering.

Resultaten visar att informationsklassning inte bör ses som en enbart operativ workshopaktivitet. I stället framställs den som en organisatorisk process som påverkas av flera organisatoriska nivåer, formad av strategisk inriktning, taktiska förberedelser och operativt genomförande. Genom att anpassa och tillämpa ett flernivåbaserat planeringsramverk på informationsklassning visar avhandlingen att de utmaningar och förutsättningar som identifieras under klassningsprocessen ofta har sitt ursprung i bristande strategisk inramning och otillräckligt taktiskt stöd. Vidare visas att klassning är en i grunden tolkande process, där subjektiva bedömningar har en viktig roll i värderingen av informationstillgångar. I kontrast till tidigare forskning, som ofta framställer subjektivitet som en svaghet som bör minimeras, omkonceptualiserar avhandlingen subjektivitet som en nödvändig komponent i meningsfulla klassningsbeslut.

Avslutningsvis identifieras två huvudsakliga vägar för att stödja klassning: automatisering och assistans. Med automatisering menas automatiseringen av främst administrativa delar av klassningen. Assistans hänvisar istället till att stödja utförandet av processens olika delar. Med utgångspunkt i ett assistansperspektiv bidrar avhandlingen till en underutvecklad del av befintliga klassningsmetoder genom att utveckla ett strukturerat dokumentationsstöd som möjliggör för deltagare i klassningsworkshops att fånga upp och dokumentera både kontextuell kunskap och beslutsmotivering. 

Place, publisher, year, edition, pages
Luleå: Luleå University of Technology, 2026
Series
Doctoral thesis / Luleå University of Technology, ISSN 1402-1544
Keywords
Information Security, Information Security Risk Management, Information Classification, Organisational Practice, Multi-level planning
National Category
Information Systems
Research subject
Information Systems
Identifiers
urn:nbn:se:ltu:diva-116736 (URN)978-91-8142-008-1 (ISBN)978-91-8142-009-8 (ISBN)
Public defence
2026-06-05, E632, Luleå University of Technology, Luleå, 09:00 (English)
Opponent
Supervisors
Available from: 2026-03-19 Created: 2026-03-18 Last updated: 2026-05-15Bibliographically approved

Open Access in DiVA

fulltext(951 kB)27 downloads
File information
File name FULLTEXT02.pdfFile size 951 kBChecksum SHA-512
e0387256021cfe71ebee887411b1825d2847587837b0670b1da5f93a0aa7340873f8a8583f65792ab50fb7ee6e9a63b54a8f5ed8d45a814b53778cbbaf0e0cc4
Type fulltextMimetype application/pdf

Other links

Publisher's full textScopus

Authority records

Andersson, Simon

Search in DiVA

By author/editor
Andersson, Simon
By organisation
Digital Services and Systems
In the same journal
Information Security Journal
Information Systems, Social aspects

Search outside of DiVA

GoogleGoogle Scholar
Total: 95 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 317 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf