【24h】

Nothing Standard About It: An Analysis of Minimum Security Standards in Organizations

机译:关于它的任何标准:分析组织中最低安全标准的分析

获取原文

摘要

Written security policies are an important part of the complex set of measures to protect organizations from adverse events. However, research detailing these policies and their effectiveness is comparatively sparse. We tackle this research gap by conducting an analysis of a specific user-oriented sub-component of a full information security policy, the Minimum Security Standard. Specifically, we conduct an analysis of 29 publicly accessible minimum security standard documents from U.S. academic institutions. We study the prevalence of an extensive set of user-oriented provisions across these statements such as who is being addressed, whether the standard is considered binding and how it is being enforced, and which specific procedures and practices for users are introduced. We demonstrate significant diversity in focus, style and comprehensiveness in this sample of minimum security standards and discuss their significance within the overall security landscape of organizations.
机译:书面安全政策是保护组织免受不利事件的复杂措施的重要组成部分。 但是,详细说明这些政策的研究和其有效性相对稀疏。 我们通过对完整信息安全策略的特定用户导向的子组件进行分析来解决这一研究差距,最低安全标准。 具体而言,我们对美国学术机构的29个公开可访问的最低安全标准文件进行了分析。 我们研究了在这些陈述中广泛的用户导向的规定的普遍性,例如正在解决谁,标准是否被视为绑定以及如何强制执行,以及推出用户的具体程序和实践。 我们在最低安全标准的这种样本中展示了重点,风格和全面性的显着多样性,并讨论了在组织整体安全景观中的重要性。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号