首页> 外文期刊>Information management & computer security >Using Penetration Testingfeedback To Cultivate An Atmosphere Of Proactive Security Amongst End-users
【24h】

Using Penetration Testingfeedback To Cultivate An Atmosphere Of Proactive Security Amongst End-users

机译:使用渗透测试反馈在最终用户中营造积极主动的安全氛围

获取原文
获取原文并翻译 | 示例

摘要

Purpose - The purpose of this case study paper is to demonstrate that, no matter how complex computer security systems are, effort should be concentrated and focused on employees to improve their security awareness. Each employee needs to become a "Security Deputy" to the company's computer security staff and he or she needs to take some responsibility for preventing security breaches - whether inside the workplace or not. It is easy to unwittingly spread a virus, or open security vulnerabilities, and such actions might damage a company's systems perhaps even more than malicious employees, through simple ignorance of security issues. Design/methodology/approach - A series of surveys and questionnaires were designed along with practical exercises and security awareness training sessions. Findings Following their involvement in the exercises and awareness training, employees demonstrated improvement in security awareness. Users were made explicitly aware of the realities of IT security with pertinent questions asked in order to force them evaluate their own reactions to a situation which may escalate into a security incident. Research limitations/implications - The research was undertaken in a typical medium-large sized company within the energy business sector, but it is possible that results may be different in other sectors. Practical implications - It is clear that security technologies alone cannot prevent incidents and therefore employees need good quality security awareness training in order to protect the organisation. Originality/value - It is becoming increasingly important that employees are taken through a more rigorous security-awareness training programme, in order to protect business computer systems and to "protect them from themselves".
机译:目的-本案例研究文件的目的是证明,无论计算机安全系统多么复杂,都应集中精力并集中精力于员工,以提高其安全意识。每位员工都需要成为公司计算机安全人员的“安全代表”,并且他或她需要承担一些防止安全漏洞的责任-无论是否在工作场所内。很容易在不知不觉中传播病毒或打开安全漏洞,并且这种行为可能通过简单地忽略安全问题而对公司系统造成的损害甚至可能超过恶意员工。设计/方法/方法-设计了一系列调查和问卷,以及实践练习和安全意识培训课程。调查结果在参与练习和意识培训之后,员工表现出对安全意识的改善。通过询问相关问题,使用户明确了解IT安全的现实,以迫使他们评估自己对可能升级为安全事件的情况的反应。研究的局限性/意义-研究是在能源行业内的一家典型的中型公司中进行的,但在其他行业中,结果可能会有所不同。实际意义-显然,仅安全技术无法防止事件发生,因此员工需要高质量的安全意识培训来保护组织。独创性/价值-员工接受更严格的安全意识培训计划变得越来越重要,以保护商业计算机系统并“保护他们免受自身侵害”。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号