Root Cause Analysis Quality Model for Corporate Security Breaches



Full text

Journal of Information System Security
Volume 17, Number 1 (2021)
Pages 330
ISSN 1551-0123
Garry L. White — Texas State University, USA
Jaymeen Shah — Texas State University, USA
Information Institute Publishing, Washington DC, USA




In this paper, we explore issues that dilute the effectiveness of Root Cause Analysis (RCA) within an organization and propose a model for RCA quality. Using the socio-organizational perspective, we grouped the issues that potentially affect the RCA quality into three factors: Environment, Person, and Process. This grouping leads to a quality RCA model for an integrated RCA thinking to identify the root cause(s) of information security incidents. This lays the foundation for further theoretical development research to address these issues and to test the RCA framework with regards to corporate information security breaches.




Root Cause Analysis, Failure Analysis Learning, Quality Model, RCA Process, Environment, Person.




