首页> 外文会议>Americas Conference on Information Systems(AMCIS 2006) vol.6 >Social Network Theoretic Framework for Organizational Social Engineering Susceptibility Index
【24h】

Social Network Theoretic Framework for Organizational Social Engineering Susceptibility Index

机译:组织社会工程敏感性指数的社会网络理论框架

获取原文

摘要

Social Engineering is an undeniable and pervasive threat to the security of information systems of an organization due to its reliance on social nature of human beings. Social engineering uses dynamic art of manipulating social behavior of human relationships to obtain unauthorized and privileged information. Corporations have pressing need to design and implement reasonable countermeasures and controls to effectively mitigate social engineering attacks. In this paper, we propose a framework for development of social engineering susceptibility index (SESI) that reveals real risks from social engineering attack that an organization's employees are exposed to. Risk managers can compute the SESI index, which is based on social network theory propositions, to understand risk exposure of a critical group of individuals or organizational departments to proactively engage in elevating security measures. The framework equips risk managers with an understanding to design better security decisions and proper policies and measures to reduce risk.
机译:由于社会工程学对人类信息系统的依赖,社会工程学对组织的信息系统安全是不可否认且普遍的威胁。社会工程学使用动态艺术来操纵人际关系的社会行为,以获得未经授权和特权的信息。公司迫切需要设计和实施合理的对策与控制措施,以有效缓解社会工程攻击。在本文中,我们提出了一个开发社会工程敏感性指数(SESI)的框架,该框架揭示了组织员工所遭受的社会工程攻击的实际风险。风险管理者可以基于社交网络理论命题计算SESI指数,以了解关键个人或组织部门群体的风险敞口,以主动采取提高安全措施的措施。该框架使风险管理人员能够了解设计更好的安全决策以及适当的策略和措施以降低风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号