首页> 外文会议>2nd international conference on security of information and networks 2009 >An Information Security Ontology Incorporating Human-Behavioural Implications
【24h】

An Information Security Ontology Incorporating Human-Behavioural Implications

机译:包含人为行为含义的信息安全本体

获取原文

摘要

Security managers often regard human behaviour as a security liability, but they should accommodate it within their organisation's information security management procedures. To further the comprehension of human-behavioural factors we develop an information security ontology. This ontology is intended for organisations that aim to maintain compliance with external standards (in this case ISO27002) while considering the security behaviours of individuals within the organisation.We demonstrate use of our ontology with an applied example concerning management of an organisation's password policy, and how it may be perceived by individuals in the organisation. We formally represent information security controls and findings regarding human behaviour, and relate these to each other and the accomplishment of standards compliance. In doing so we provide a model that information security managers can use to consider the impact of their security management decisions.
机译:安全管理人员通常将人的行为视为安全责任,但他们应将其纳入组织的信息安全管理程序中。为了进一步理解人为行为因素,我们开发了一种信息安全本体。该本体适用于旨在维持外部标准(在本例中为ISO27002)的合规性,同时考虑组织内个人的安全行为的组织。 我们通过一个有关组织密码策略管理以及组织中的个人如何看待该示例的应用示例演示了本体的使用。我们正式代表有关人类行为的信息安全控制和调查结果,并将它们彼此联系起来并实现标准合规性。通过这样做,我们提供了一个模型,信息安全管理人员可以使用该模型来考虑其安全管理决策的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号