首页> 外文期刊>European journal of information systems >Opportunities for computer crime: considering systems risk from a criminological perspective
【24h】

Opportunities for computer crime: considering systems risk from a criminological perspective

机译:计算机犯罪的机会:从犯罪学角度考虑系统风险

获取原文
获取原文并翻译 | 示例
       

摘要

Systems risk refers to the likelihood that an Information System (IS) is inadequately protected against certain types of damage or loss. While risks are posed by acts of God, hackers and viruses, consideration should also be given to the 'insider' threat of dishonest employees, intent on undertaking some form of computer crime. Against this backdrop, a number of researchers have addressed the extent to which security managers are cognizant of the very nature of systems risk. In particular, they note how security practitioners' knowledge of local threats, which form part of such risk, is often fragmented. This shortcoming contributes to situations where risk reducing efforts are often less than effective. Security efforts are further complicated given that the task of managing systems risk requires input from a number of departments including, for example, HR, compliance, IS/IT and physical security. To complement existing research, and also to offer a fresh perspective, this paper addresses systems risk from the offender's perspective. If systems risk entails the likelihood that an IS is inadequately protected, this text considers those conditions, within the organisational context, which offer a criminal opportunity for the offender. To achieve this goal a model known as the 'Crime-Specific Opportunity Structure' is advanced. Focusing on the opportunities for computer crime, the model addresses the nature of such opportunities with regards to the organisational context and the threats posed by rogue employees. Drawing on a number of criminological theories, it is believed the model may help inform managers about local threats and, by so doing, enhance safeguard implementation.
机译:系统风险是指信息系统(IS)受到适当保护以免遭受某些类型的损坏或损失的可能性。尽管风险是由上帝的行为,黑客和病毒造成的,但也应考虑不诚实员工的“内部”威胁,意图进行某种形式的计算机犯罪。在这种背景下,许多研究人员已经讨论了安全管理人员在多大程度上意识到系统风险的本质。他们特别指出,安全从业者对构成这种风险一部分的本地威胁的知识通常是分散的。这种缺点导致了减少风险的努力通常效果不佳的情况。鉴于管理系统风险的任务需要来自多个部门的意见,包括人力资源,合规性,IS / IT和物理安全性,安全工作变得更加复杂。为了补充现有研究并提供崭新的视角,本文从犯罪者的角度探讨了系统风险。如果系统风险带来了对IS的保护不足的可能性,则本文将在组织范围内考虑为犯罪者提供犯罪机会的那些条件。为了实现这一目标,提出了一种称为“犯罪特定机会结构”的模型。该模型着眼于计算机犯罪的机会,从组织环境和流氓员工所构成的威胁方面探讨了此类机会的性质。根据许多犯罪学理论,可以认为该模型可以帮助管理人员了解当地的威胁,并通过这样做来增强保障措施的实施。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号