首页> 中文学位 >Evaluating the Human Factor in Information Security Risk Management in Business Organizations
【6h】

Evaluating the Human Factor in Information Security Risk Management in Business Organizations

代理获取

目录

封面

封面

声明

英文摘要

目录

List of Figures

List of Tables

CHAPTER 1–INTRODUCTION

1.1 Background and Motivation

1.2Aim of Research

1.3 Main Work of Thesis

1.4 Organization of Thesis

CHAPTER 2-LITERATURE REVIEW

2.1 Risk Management

2.2 Business Organization Risks

2.3 The Human Element In Risk

2.4 Risk Communication

2.5 Education and Training

2.6 Behavioral Change

CHAPTER 3–HUMAN FACTOR IN RISK MANAGEMENT RESEARCH APPROACH

3.1 Research Method Types

3.2 The Research Process

3.3 Human Factors Risk Management Survey

CHAPTER 4–SURVEY RESULTS AND HYPOTHESES EVALUATION

4.1 Data Collection

4.2 Data Analysis

4.3 Data Coding

4.4 Data Interpretation

4.5 General Observations

4.6 First Hypothesis

4.7 Second Hypothesis

4.8 Third Hypothesis

4.9 Fourth Hypothesis

4.10 Fifth Hypothesis

CONCLUSIONS

参考文献

致谢

APPENDIX

展开▼

摘要

Information Security has become a critical issue in business organizations. Organizations continue to face all kinds of security risks. Technological solutions are being sought to control risks, experts are consulted to impact their specialized knowledge, third-party companies are being outsourced to avail their skilled and experienced staff to curb the menace. One main factor in controlling security risks in business organizations is the human element. This paper takes a look into the human factors that affect information security risk management in business organizations.
The paper aims to evaluate the human factors that affect the risk control measures that are implemented in business organizations. This research collects information from employees in business organizations about their security behaviors in the working environment. The study is mainly based on an online survey conducted with the employees in three business organizations. Fictitious names were used in this report because of confidential reasons on the part of the companies. The link to the questions was distributed to the employees by email with the help of the companies’ information technology departments. The questions were based on four user properties that cover various aspects of risk management. They were population, security policy, risk communication and security education, training and awareness. The survey data was analyzed and five proposed hypotheses were evaluated. Some of the hypothesis were confirmed whiles some were refuted based on the analyzed survey data.
From the results, a number of conclusions were made. Organizations should include information security briefing as part of this orientation programs. This gives the user a prior security awareness mindset. This research has shown that user risks perception cuts across all employee levels so the same amount of effort should be put in to educate and train all employees on security risk awareness. Users should have some education on organizational policies even if they were involved in the creation process. Policies should be communicated properly to users and the users should be made to sign to agree to the policies that they’ve read. Organizations should implement appropriate measures to penalize employees as this could lead to employees covering their errors and mistakes especially when they themselves are in the wrong. Training programs should address user-training needs. Users’ view could be sought before organizing training programs and they should be after training programs to evaluate the effectiveness of the training. This helps to improve on the quality of training programs.

著录项

相似文献

  • 中文文献
  • 外文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号