首页> 外文会议>International Conference on Cyber Situational Awareness, Data Analytics and Assessment >Revolution and stability in the study of the human factor in the security of information systems field : A systematic literature review over 30 years of publication
【24h】

Revolution and stability in the study of the human factor in the security of information systems field : A systematic literature review over 30 years of publication

机译:信息系统安全性研究人文因素研究中的革命与稳定性:30多年出版物的系统文献综述

获取原文

摘要

Human factor is widely recognized as the first threat to the security of information systems (ISS). ISS research thus points to the problem of user behavior, which is overwhelmingly represented as a fallibility that would be part of its nature. Companies would therefore have no choice but to anticipate these behaviors in order to reinforce the security of the information system. However, despite all the collective legitimacy contributing to the "normal" evolution of this field of research, could we think differently this problem? We therefore conducted a critical review of the literature on the human factor in information system security publications over 31 years (between 1989 and 2020). Our results draw the details of a normal science that has developed and deepened our knowledge of human behavior to protect an information system. We discovered that this main knowledge production shares structural epistemic and moral assumptions. These researchers’ choices are problematic since they are implicit and consequently raise concern about a very partial and simplifying representation of user’s contribution to a good security. We advocate for the development of alternative epistemic and moral choices to nourish the evolution of the current paradigmatic consensus. This alternative agenda is likely to improve recommendations for practice while showing a greater objectivity.
机译:人为因素被广泛认可为对信息系统安全性的第一种威胁(ISS)。因此,ISS研究指出了用户行为的问题,这绝大多数表示为其本质的一部分。因此,公司别无选择,只能预测这些行为,以加强信息系统的安全。但是,尽管集体合法性贡献了这项研究领域的“正常”演变,但我们可以思考这个问题吗?因此,我们对信息系统安全出版物的人为因素(1989年至2020年间)进行了对人类安全出版物的人类因素的关键审查。我们的结果绘制了一项正常科学的细节,这些科学已经开发并加深了我们对人类行为知识来保护信息系统的知识。我们发现,这一主要知识产量股份结构性认知和道德假设。这些研究人员的选择是有问题的,因为它们是隐含的,因此引起了对用户对良好安全性贡献的贡献非常部分和简化的关注。我们倡导开发替代认识和道德选择,以滋养目前的范式共识的演变。此替代议程可能会改善练习的建议,同时表现出更大的客观性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号