In this short paper we argue that to combat APTs, organizations need a strategic level shift away from a traditional prevention centered approach to that of a response centered one. Drawing on the information warfare (IW) paradigm in military studies, and using Dynamic Capability Theory (DCT), this research examines the applicability of IW capabilities in the corporate domain. We propose a research framework to argue that conventional prevention centred response capabilities; such as incident response capabilities and IW centred security capabilities can be integrated into IW enabled dynamic response capabilities that improve enterprise security performance.
翻译:在这份简短的文件中,我们争论说,为了打击防止酷刑,各组织需要从传统的以预防为中心的方法转向以反应为中心的方法。 根据军事研究中的信息战范式以及动态能力理论(DCT ), 这项研究审视了IW能力在公司领域的适用性。 我们提出了一个研究框架,以论证常规预防中心反应能力,例如事故反应能力和IW中心安全能力,可以纳入IW的动态反应能力,从而提高企业安全性能。