首页> 外文期刊>Information management & computer security >Mitigating cyber attacks through the measurement of non-IT professionals' cybersecurity skills
【24h】

Mitigating cyber attacks through the measurement of non-IT professionals' cybersecurity skills

机译:通过衡量非IT专业人员的网络安全技能来缓解网络攻击

获取原文
获取原文并翻译 | 示例
       

摘要

Purpose - Users' mistakes due to poor cybersecurity skills result in up to 95 per cent of cyber threats to organizations. Threats to organizational information systems continue to result in substantial financial and intellectual property losses. This paper aims to design, develop and empirically test a set of scenarios-based hands-on tasks to measure the cybersecurity skills of non-information technology (IT) professionals. Design/methodology/approach - This study was classified as developmental in nature and used a sequential qualitative and quantitative method to validate the reliability of the Cybersecurity Skills Index (CSV) as a prototype-benchmarking tool. Next, the prototype was used to empirically test the demonstrated observable hands-on skills level of 173 non-IT professionals. Findings - The importance of skills and hands-on assessment appears applicable to cybersecurity skills of non-IT professionals. Therefore, by using an expert-validated set of cybersecurity skills and scenario-driven tasks, this study established and validated a set of hands-on tasks that measure observable cybersecurity skills of non-IT professionals without bias or the high-stakes risk to IT. Research limitations/implications - Data collection was limited to the southeastern USA and while the sample size of 173 non-IT professionals is valid, further studies are required to increase validation of the results and generalizability. Originality/value - The validated and reliable CSI operationalized as a tool that measures the cybersecurity skills of non-IT professionals. This benchmarking tool could assist organizations with mitigating threats due to vulnerabilities and breaches caused by employees due to poor cybersecurity skills.
机译:目的-由于网络安全技能差而导致的用户错误,导致高达95%的组织面临网络威胁。组织信息系统的威胁继续导致重大的财务和知识产权损失。本文旨在设计,开发和经验测试一组基于场景的动手任务,以衡量非信息技术(IT)专业人员的网络安全技能。设计/方法/方法-这项研究在本质上被归类为发展性研究,并使用顺序定性和定量方法来验证网络安全技能指数(CSV)作为原型基准测试工具的可靠性。接下来,该原型用于对173名非IT专业人员的实践技能水平进行实证测试。调查结果-技能和动手评估的重要性似乎适用于非IT专业人员的网络安全技能。因此,通过使用一组经过专家验证的网络安全技能和由场景驱动的任务,本研究建立并验证了一组动手任务,这些任务可测量非IT专业人员可观察到的网络安全技能,而不会产生偏见或对IT构成高风险。研究的局限性/意义-数据收集仅限于美国东南部,虽然173名非IT专业人员的样本量是有效的,但仍需要进一步研究以提高结果的确认性和可推广性。原创性/价值-经过验证且可靠的CSI可作为一种工具来衡量非IT专业人员的网络安全技能。该基准测试工具可以帮助组织缓解由于脆弱的网络安全技能而导致的漏洞和员工造成的漏洞所带来的威胁。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号