首页> 外文会议>Americas Conference on Information Systems >Social Network Theoretic Framework for Organizational Social Engineering Susceptibility Index
【24h】

Social Network Theoretic Framework for Organizational Social Engineering Susceptibility Index

机译:组织社会工程易感性指数的社会网络理论框架

获取原文
获取外文期刊封面目录资料

摘要

Social Engineering is an undeniable and pervasive threat to the security of information systems of an organization due to its reliance on social nature of human beings. Social engineering uses dynamic art of manipulating social behavior of human relationships to obtain unauthorized and privileged information. Corporations have pressing need to design and implement reasonable countermeasures and controls to effectively mitigate social engineering attacks. In this paper, we propose a framework for development of social engineering susceptibility index (SESI) that reveals real risks from social engineering attack that an organization's employees are exposed to. Risk managers can compute the SESI index, which is based on social network theory propositions, to understand risk exposure of a critical group of individuals or organizational departments to proactively engage in elevating security measures. The framework equips risk managers with an understanding to design better security decisions and proper policies and measures to reduce risk.
机译:由于其依赖于人类的社会性质,社会工程是对组织信息系统安全的不可否认和普遍的威胁。社会工程使用动态艺术来操纵人际关系的社会行为,以获得未经授权和特权的信息。公司需要迫切需要设计和实施合理的对策和控制,以有效缓解社会工程攻击。在本文中,我们向社会工程易感性指数(SESI)提出了一种框架,揭示了社会工程攻击的真正风险,即组织的员工接触到。风险管理人员可以计算基于社交网络理论主张的SESI指数,了解一群关键人或组织部门的风险暴露,以主动地接受安全措施。该框架配备风险管理人员,了解更好的安全决策和适当的政策和措施,以降低风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号