首页> 外文会议>IEEE Central America and Panama Convention >Social Engineering for Diagnostic the Information Security Culture
【24h】

Social Engineering for Diagnostic the Information Security Culture

机译:诊断信息安全文化的社会工程学

获取原文

摘要

In the process of diagnosing the culture of information security in an organization, it is considered two methods, the first one is the application of an ISCA (Information Security Culture Assessment) survey questionnaire and the second one based on social engineering techniques such as phishing, answering the question, How can a diagnosis be made effectively of the level of information security culture within an organization? with the objective of determining which of the two methods is the most effective and realistic for the diagnosis of the information security culture. This helps to understand and have a real and complete perception of the behavior and reaction of the users against the attacks of threat actors who make use of persuasion and manipulation tactics in order to obtain confidential or sensitive information. A description of these two methods is applied to a case study (public university). As a result, it is obtained that it is not enough to perform a diagnosis based on questionnaires because they can be relatively subjective in the sense of the way in which users respond to questions or statements. Evidence of controlled social engineering attacks that demonstrate in more detail the real behavior of users should be considered. Based on this more complete knowledge, appropriate strategies can be formulated for the change or strengthening of the security culture that ultimately contributes to the purpose of protecting information assets.
机译:在诊断组织中的信息安全文化的过程中,有两种方法,一种是应用ISCA(信息安全文化评估)调查问卷,另一种是基于网络钓鱼等社会工程技术,回答这个问题:如何有效地诊断组织内的信息安全文化水平?目的是确定两种方法中的哪一种对信息安全文化的诊断最有效和最现实。这有助于了解并真实,完整地理解用户对使用诱使和操纵策略以获取机密或敏感信息的威胁行为者的攻击所采取的行为和反应。这两种方法的描述适用于案例研究(公立大学)。结果,获得基于问卷的诊断是不够的,因为在用户回答问题或陈述的方式上,问卷可能是相对主观的。应当考虑有控制的社会工程学攻击的证据,它可以更详细地说明用户的真实行为。基于这些更全面的知识,可以制定适当的策略来更改或加强安全文化,最终有助于保护信息资产。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号