Appendix A: Action Research Cycles

This appendix provides an overview of the action research cycles and subcycles undertaken during the research study to understand the field of information security risk management from the practices in the two organizations, ALPHA and BETA.

Figure A.1 summarizes information risk management framework as part of this study. It shows a data analysis (DA) step at the end of each of six major cycles. The dotted lines at the DA steps indicate the scope of coverage of the steps that encompassed the interpretations and reflections of the data collected in that cycle as well as the output of data analysis from all previously completed cycles.

From a meta-methodology perspective, the six cycles are divided into four main ...

Get Responsive Security now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.