首页> 外文期刊>Information management & computer security >An information security risk-driven investment model for analysing human factors
【24h】

An information security risk-driven investment model for analysing human factors

机译:信息安全风险驱动的人为因素分析投资模型

获取原文
获取原文并翻译 | 示例
           

摘要

Purpose - The purpose of this paper is to introduce a risk-driven investment process model for analysing human factors that allows information security managers to capture possible risk-investment relationships and to reason about them. The overall success of an information security system depends on analysis of the risks and threats so that appropriate protection mechanism can be in place to protect them. However, lack of appropriate analysis of risks may potentially results in failure of information security systems. Existing literature does not provide adequate guidelines for a systematic process or an appropriate modelling language to support such analysis. This work aims to fill this gap by introducing the process and reason about the risks considering human factors. Design/methodology/approach - To develop risk-driven investment model along with the activities that support the process. These objectives were achieved through the collection of quantitative and qualitative data utilising requirements engineering and secure tropos methods. Findings - The proposed process and model lead to define a clear relationship between risks, incidents and investment and allows organisations to calculate them based on their own figures. Research limitations/implications - One of the major limitations of this model is that it only supports incident-based investment. This creates some sort of difficulties to be presented to the executive board. Secondly, because of the nature of human factors, quantification does not exactly reflect the monetary value of the factors. Practical implications - Applying the information security risk-driven investment model in a real case study shows that this can help organisations apply and use it in other incidents, and more importantly, to the incidents which critical human factors are a grave concern of organisations. The importance of providing a financial justification is clearly highlighted and provided for seeking investment in information security. Social implications - It has a big social impact that technically could lead for cost justifications and decision-making process. This would impact the whole society by helping individuals to keep their data safe. Originality/value - The novel contribution of this work is to analyse specific critical human factors which have subjective natures in an objective and dynamic domain of risk, security and investment.
机译:目的-本文的目的是介绍一种风险驱动的投资过程模型,用于分析人为因素,从而使信息安全经理可以捕获可能的风险与投资关系并对其进行推理。信息安全系统的总体成功取决于对风险和威胁的分析,以便可以建立适当的保护机制来保护它们。但是,缺乏适当的风险分析可能会导致信息安全系统故障。现有文献没有为系统过程或适当的建模语言提供适当的指导以支持此类分析。这项工作旨在通过介绍考虑人为因素的风险的过程和原因来填补这一空白。设计/方法/方法-与支持流程的活动一起开发风险驱动的投资模型。这些目标是通过使用需求工程和安全的对位方法收集定量和定性数据来实现的。结果-提议的流程和模型可以定义风险,事件和投资之间的明确关系,并允许组织根据自己的数字进行计算。研究局限性/含义-该模型的主要局限性之一是它仅支持基于事件的投资。这给执行委员会带来了一些困难。其次,由于人为因素的性质,量化不能完全反映人为因素的货币价值。实际意义-在实际案例研究中应用信息安全风险驱动的投资模型表明,这可以帮助组织在其他事件中应用和使用它,更重要的是,可以解决关键人为因素是组织严重关注的事件。明确强调了提供财务理由的重要性,并提供了寻求信息安全方面的投资的重要性。社会影响-从技术上讲,这可能会导致巨大的社会影响,导致成本合理性和决策过程。这将通过帮助个人保持数据安全来影响整个社会。原创性/价值-这项工作的新颖贡献是分析特定的关键人为因素,这些因素在风险,安全性和投资的客观动态范围内具有主观性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号