首页> 外文会议>Americas conference on information systems >Examination of Organizational Information Security Strategy: A Pilot Study
【24h】

Examination of Organizational Information Security Strategy: A Pilot Study

机译:考察组织信息安全战略:试点研究

获取原文

摘要

The prevailing approach to cyber security continues to be the implementation of controls-technical, formal, and informal. We have seen little departure from a fundamentally preventive strategy. The criminal justice field has called for an increased emphasis on deterrence strategies, specifically Situational Crime Prevention (SCP). This paper presents the results of an exploratory (pilot) study based on interviews of CISOs (or approximate equivalents). We found that while the balance of controls does appear to be improving, technical controls are still the priority-particularly in small organizations. We found that IS security strategies are still predominantly preventive; organizations do not view offender deterrence as a strategy. The respondents definitely see room for strategic improvement. By and large, the information security professionals interviewed believe that cyber offenders are rational decision makers, that reducing anticipated benefit would be the most lucrative influence, followed by perceived effort required and perceived risk of being caught, in that order.
机译:网络安全的流行方法仍然是实施控制 - 技术,正式和非正式的。我们从根本预防措施中脱离了。刑事司法领域呼吁增加对威慑策略,特别是境地预防犯罪(SCP)。本文介绍了基于CisoS访谈(或近似等同物)的探索性(飞行员)研究的结果。我们发现,虽然对照的平衡似乎是有所改善,但技术控制仍然是优先级 - 特别是在小型组织中。我们发现安全策略仍然主要预防;组织不将罪犯威慑视为战略。受访者肯定会看到战略改善的空间。 By Andly,信息安全专业人士采访认为,网络罪犯是合理的决策者,降低预期的福利是最有利可图的影响,其次是所需的努力和感知被抓住的风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号