首页> 外文学位 >A Qualitative Meta-synthesis on the Benefits of Planning for Ransomware Attacks at a Strategic Organizational Level
【24h】

A Qualitative Meta-synthesis on the Benefits of Planning for Ransomware Attacks at a Strategic Organizational Level

机译:关于在战略组织层面规划勒索软件攻击的好处的定性元综合

获取原文
获取原文并翻译 | 示例

摘要

The problem addressed in this meta-synthesis was that many organizations have become or will become victims of massive data losses caused by ransomware attacks because ransomware security controls and data loss prevention are not prioritized during strategic planning. The study's conceptual framework was built upon the core principles that many of the ill-effects of data loss that may result from a cyberattack or data breach are preventable with the proper use of security controls that organizational leaders often fail to prioritize during strategic planning. In an effort to examine if strategically prioritizing malware and ransomware protection through the use of security controls and implementing specific recommended actions may reduce the effects of data loss on an organization, the following research questions were developed: What are the commonalities in causes of ransomware attacks that resulted in highly impactful data breaches for the organizations examined in this meta-synthesis multiple case study? What specific actions can organizations take to mitigate or reduce the effects of ransomware attacks? What recommendations can be made regarding effective controls, policies, and procedures for the mitigation of ransomware attacks to prevent data loss? This study used a qualitative research design based on meta-synthesis of six selected qualitative case studies, chosen for their newsworthiness and effects on both the victim organization and its affected customers, using a thematic synthesis approach in an effort to unite common cause and effect connections among them. From the analysis of the case studies, four themes emerged: a lack of strategic planning; the inability to recognize network anomalies; the lack of or misuse of security controls; and the consequences of not putting effort into mitigating the data breaches.Keywords: malware, ransomware, data breach, data loss, strategic planning.
机译:这个元综合解决的问题是,许多组织已经或将要成为勒索软件攻击造成的大量数据丢失的受害者,因为勒索软件安全控制和数据丢失预防在战略规划中没有得到优先考虑。该研究的概念框架建立在核心原则之上,即网络攻击或数据泄露可能导致的许多数据丢失不良影响可以通过正确使用安全控制措施来预防,而组织领导者在战略规划期间往往没有优先考虑这些控制。为了检查通过使用安全控制措施和实施具体的建议措施来战略性地优先考虑恶意软件和勒索软件保护是否可以减少数据丢失对组织的影响,我们提出了以下研究问题:勒索软件攻击的原因有哪些共性,这些攻击导致了对本元综合多个案例研究中研究的组织产生高度影响的数据泄露?组织可以采取哪些具体措施来减轻或减少勒索软件攻击的影响?对于缓解勒索软件攻击以防止数据丢失的有效控制、策略和程序,可以提出哪些建议?本研究采用了基于六个选定定性案例研究的元综合的定性研究设计,这些案例研究是根据它们的新闻价值和对受害者组织及其受影响客户的影响而被选中的,使用主题综合方法努力将它们之间的共同因果联系统一起来。从对案例研究的分析中,出现了四个主题:缺乏战略规划;无法识别网络异常;缺乏或滥用安全控制措施;以及不努力减少数据泄露的后果。关键词:恶意软件、勒索软件、数据泄露、数据丢失、战略规划。

著录项

  • 作者

    Snyder, Danielle L.;

  • 作者单位

    Colorado Technical University.;

    Colorado Technical University.;

    Colorado Technical University.;

  • 授予单位 Colorado Technical University.;Colorado Technical University.;Colorado Technical University.;
  • 学科 Computer science.
  • 学位
  • 年度 2022
  • 页码 137
  • 总页数 137
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Computer science.;

    机译:计算机科学。;
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号