首页> 外文学位 >Standardizing Instructional Definition and Content Supporting Information Security Compliance Requirements
【24h】

Standardizing Instructional Definition and Content Supporting Information Security Compliance Requirements

机译:标准化教学定义和内容支持信息安全合规性要求

获取原文
获取原文并翻译 | 示例

摘要

Information security (IS)-related risks affect global public and private organizations on a daily basis. These risks may be introduced through technical or human-based activities, and can include fraud, hacking, malware, insider abuse, physical loss, mobile device misconfiguration or unintended disclosure.;Numerous and diverse regulatory and contractual compliance requirements have been mandated to assist organizations proactively prevent these types of risks. Two constants are noted in these requirements. The first constant is requiring organizations to disseminate security policies addressing risk management through secure behavior. The second constant is communicating policies through IS awareness, training and education (ISATE) programs. Compliance requirements direct that these policies provide instruction about making compliant and positive security decisions to reduce risk. Policy-driven and organizationally-relevant ISATE content is understood to be foundational and critical to prevent security risk.;The problem identified for investigation is inconsistency of the terms awareness, training and education as found in security-related regulatory, contractual and policy compliance requirements. Organizations are mandated to manage a rapidly increasing portfolio of inconsistent ISATE compliance requirements generated from many sources. Since there is no one set of common guidance for compliance, organizations struggle to meet global, diverse and inconsistent compliance requirements. Inconsistent policy-related content and instructions, generated from differing sources, may cause incorrect security behavior that can present increased security risk. Traditionally, organizations were required to provide only internally-developed programs, with content left to business, regulatory/contractual, and cultural discretion. Updated compliance requirements now require organizations to disseminate externally-developed content in addition to internally-provided content. This real-world business requirement may cause compliance risks due to inconsistent instruction, guidance gaps and lack of organizational relevance.;The problem has been experienced by industry practitioners within the last five years due to increased regulatory and contractual compliance requirements. Prior studies have not yet identified specific impacts of multiple and differing compliance requirements on organizations. The need for organizational relevance in ISATE content has been explored in literature, but the amount of organizationally-relevant content has not been examined in balance of newer compliance mandates.;The goal of the research project was to develop a standard content definition and framework. Experienced practitioners responsible for ISATE content within their organizations participated in a survey to validate definitions, content, compliance and organizational relevance requirements imposed on their organizations. Fifty-five of 80 practitioners surveyed (68.75% participation rate) provided responses to one or more sections of the survey.;This research is believed to be the first to suggest a standardized content definition for ISATE program activities based on literature review, assessment of existing regulatory, contractual, standard and framework definitions and information obtained from specialized practitioner survey data. It is understood to be the first effort to align and synthesize cross-industry compliance requirements, security awareness topics and organizational relevance within information security awareness program content.;Findings validated that multiple and varied regulatory and contractual compliance requirements are imposed on organizations. A lower number of organizations were impacted by third party program requirements than was originally expected. Negative and positive impacts of third party compliance requirements were identified. Program titles and content definitions vary in respondent organizations and are documented in a variety of organizational methods. Respondents indicated high acceptance of a standard definition of awareness, less so for training and education. Organizationally-relevant program content is highly important and must contain traditional and contemporary topics.;Results are believed to be an original contribution to information/cyber security practitioners, with findings of interest to academic researchers, standards/framework bodies, auditing/risk management practitioners and learning/development specialists.
机译:与信息安全(IS)相关的风险每天都会影响全球公共和私人组织。这些风险可能是通过技术或基于人员的活动而引入的,其中可能包括欺诈,黑客攻击,恶意软件,内部滥用,物理损失,移动设备配置错误或意外泄露。已强制要求多种多样的法规和合同合规性要求以帮助组织积极预防此类风险。这些要求中指出了两个常数。第一个常数是要求组织传播通过安全行为解决风险管理的安全策略。第二个常数是通过IS意识,培训和教育(ISATE)计划传达政策。法规遵从要求指示这些策略提供有关制定法规和积​​极的安全决策以降低风险的指导。政策驱动且与组织相关的ISATE内容被认为是预防安全风险的基础和关键。确定要调查的问题是与安全相关的法规,合同和政策合规性要求中存在的意识,培训和教育术语不一致。组织受权管理由许多来源产生的,不一致的ISATE合规要求迅速增长的产品组合。由于没有一套通用的合规指南,因此组织难以满足全球,多样化和不一致的合规要求。从不同来源生成的与策略相关的内容和说明不一致,可能会导致错误的安全行为,从而增加安全风险。传统上,要求组织仅提供内部开发的程序,其内容留给业务,监管/合同和文化判断。现在,更新的合规性要求要求组织除了内部提供的内容之外,还传播外部开发的内容。由于不一致的指令,指导差距和缺乏组织相关性,这种现实世界的业务需求可能会导致合规风险。;由于法规和合同合规要求的提高,行业从业人员在过去五年中遇到了此问题。先前的研究尚未确定多种和不同的合规性要求对组织的特定影响。文献中已经探讨了在ISATE内容中具有组织相关性的需求,但是尚未在新的合规性要求之间取得平衡来研究与组织相关的内容的数量。研究项目的目的是开发标准的内容定义和框架。负责组织内部ISATE内容的经验丰富的从业人员参加了一项调查,以验证对组织施加的定义,内容,合规性和组织相关性要求。在接受调查的80位从业人员中,有55位(68.75%的参与率)对调查的一个或多个部分做出了回应。该研究被认为是第一个提出基于文献综述,评估对ISATE计划活动的标准化内容定义的研究。现有的法规,合同,标准和框架定义以及从专业从业者调查数据中获得的信息。可以理解,这是在信息安全意识计划的内容范围内协调和综合跨行业的合规性要求,安全意识主题和组织相关性的第一项努力。研究发现,对组织施加了多种多样的法规和合同合规性要求。受第三方计划要求影响的组织数量比最初预期的要少。确定了第三方合规要求的负面影响和积极影响。程序标题和内容定义在响应组织中有所不同,并以多种组织方法进行了记录。受访者表示,他们对意识的标准定义表示高度认可,而对于培训和教育则不那么认为。与组织相关的计划内容非常重要,并且必须包含传统和现代主题。;结果被认为是对信息/网络安全从业人员的原始贡献,研究人员,标准/框架机构,审计/风险管理从业人员都对研究结果感兴趣和学习/发展专家。

著录项

  • 作者

    Curran, Terri Theresa.;

  • 作者单位

    Nova Southeastern University.;

  • 授予单位 Nova Southeastern University.;
  • 学科 Information science.;Computer science.;Educational administration.
  • 学位 Ph.D.
  • 年度 2018
  • 页码 131 p.
  • 总页数 131
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

  • 入库时间 2022-08-17 11:53:30

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号