...
首页> 外文期刊>Computers & Security >Challenges in IT security preparedness exercises: A case study
【24h】

Challenges in IT security preparedness exercises: A case study

机译:IT安全准备工作中的挑战:一个案例研究

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

The electric power industry is currently implementing major technological changes in order to achieve the goal of smart grids. However, these changes are expected to increase the susceptibility of the industry to IT security incidents. IT security preparedness exercises are not commonly performed in the electric power industry, even though this industry is considered part of society's critical infrastructure. Resolving an IT security incident requires inter-departmental collaborations between various categories of personnel, and to successfully achieve this, training is required. The process of preparing a response to incidents enhances the nature of collaboration, coordination, and communication within an organization. Our objective is to understand the challenges faced when performing IT security preparedness exercises, as challenges experienced during these exercises affect the response process during a real incident. By improving the exercises, the response capabilities would be strengthened accordingly. We have designed a multiple-case study with six teams in three organizations. We collected data by performing semi-structured interviews, participant observations, and from process artifacts. We identified six main challenges involving team composition and external expert involvement, goal definition, documentation, and time management. In summary, there are many ways of conducting preparedness exercises. Therefore, organizations need to both optimize current exercise practices and experiment with new ones in order to ensure continuous learning and improvement; hence, they can be adequately prepared to respond to IT security incidents.
机译:电力行业目前正在实施重大技术变革,以实现智能电网的目标。但是,这些更改预计会增加该行业对IT安全事件的敏感性。尽管电力行业被认为是社会关键基础设施的一部分,但在电力行业通常不进行IT安全准备工作。解决IT安全事件需要各类人员之间的部门间协作,而要成功实现这一目标,则需要培训。准备事件响应的过程增强了组织内部协作,协调和沟通的本质。我们的目标是了解执行IT安全准备练习时面临的挑战,因为在这些练习中遇到的挑战会影响实际事件中的响应过程。通过改进练习,应对能力将得到相应增强。我们设计了一个多案例研究,在三个组织中有六个团队。我们通过执行半结构化访谈,参与者观察以及过程工件来收集数据。我们确定了六个主要挑战,包括团队组成和外部专家参与,目标定义,文档编制和时间管理。总之,有许多进行准备工作的方法。因此,组织既需要优化当前的练习方法,又需要尝试新的练习方法,以确保不断学习和改进。因此,他们可以充分准备应对IT安全事件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号