...
首页> 外文期刊>Computers & Security >A framework and assessment instrument for information security culture
【24h】

A framework and assessment instrument for information security culture

机译:信息安全文化的框架和评估工具

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

An organisation's approach to information security should focus on employee behaviour, as the organisation's success or failure effectively depends on the things that its employees do or fail to do. An information security-aware culture will minimise risks to information assets and specifically reduce the risk of employee misbehaviour and harmful interaction with information assets. Organisations require guidance in establishing an information security-aware or implementing an acceptable information security culture. They need to measure and report on the state of information security culture in the organisation. Various approaches exist to address the threats that employee behaviour could pose. However, these approaches do not focus specifically on the interaction between the behaviour of an employee and the culture in an organisation. Organisations therefore have need of a comprehensive framework to cultivate a security-aware culture. The objective of this paper is to propose a framework to cultivate an information security culture within an organisation and to illustrate how to use it. An empirical study is performed to aid in validating the proposed Information Security Culture Framework.
机译:组织的信息安全方法应关注员工的行为,因为该组织的成功或失败实际上取决于其员工做或不做的事情。具有信息安全意识的文化将最大程度地降低信息资产的风险,并特别降低员工行为不当以及与信息资产进行有害互动的风险。组织需要建立信息安全意识或实施可接受的信息安全文化的指导。他们需要衡量并报告组织中信息安全文化的状况。存在各种方法来应对员工行为可能造成的威胁。但是,这些方法并不专门关注员工行为与组织文化之间的相互作用。因此,组织需要一个全面的框架来培养安全意识的文化。本文的目的是提出一个框架,以在组织内培养信息安全文化并说明如何使用它。进行了一项经验研究,以帮助验证提议的信息安全文化框架。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号