...
首页> 外文期刊>Information management & computer security >Developing cybersecurity education and awareness programmes for small- and medium-sized enterprises (SMEs)
【24h】

Developing cybersecurity education and awareness programmes for small- and medium-sized enterprises (SMEs)

机译:为中小企业制定网络安全教育和意识计划

获取原文
获取原文并翻译 | 示例
           

摘要

Purpose - The purpose of this study is to focus on organisation's cybersecurity strategy and propose a high-level programme for cybersecurity education and awareness to be used when targeting small- and medium-sized enterprises/businesses (SMEs/SMBs) at a city-level. An essential component of an organisation's cybersecurity strategy is building awareness and education of online threats and how to protect corporate data and services. This programme is based on existing research and provides a unique insight into an ongoing city-based project with similar aims. Design/methodology/approach - To structure this work, a scoping review was conducted of the literature in cybersecurity education and awareness, particularly for SMEs/SMBs. This theoretical analysis was complemented using a case study and reflecting on an ongoing, innovative programme that seeks to work with these businesses to significantly enhance their security posture. From these analyses, best practices and important lessons/recommendations to produce a high-level programme for cybersecurity education and awareness were recommended. Findings - While the literature can be informative at guiding education and awareness programmes, it may not always reach real-world programmes. However, existing programmes, such as the one explored in this study, have great potential, but there can be room for improvement. Knowledge from each of these areas can, and should, be combined to the benefit of the academic and practitioner communities. Originality/value - The study contributes to current research through the outline of a high-level programme for cybersecurity education and awareness targeting SMEs/SMBs. Through this research, literature in this space was examined and insights into the advances and challenges faced by an on-going programme were presented. These analyses allow us to craft a proposal for a core programme that can assist in improving the security education, awareness and training that targets SMEs/SMBs.
机译:目的-这项研究的目的是集中于组织的网络安全策略,并提出针对网络安全教育和意识的高级别计划,以针对城市一级的中小型企业/企业(SME / SMB) 。组织网络安全策略的重要组成部分是提高对在线威胁以及如何保护公司数据和服务的意识和教育。该计划基于现有研究,并为正在进行中且目标相似的城市项目提供了独特的见解。设计/方法/方法-为组织这项工作,对网络安全教育和意识方面的文献进行了范围界定审查,特别是针对中小企业/中小型企业。通过案例研究对这一理论分析进行了补充,并反思了一个正在进行的创新计划,该计划旨在与这些企业合作以显着增强其安全状况。从这些分析中,建议了最佳实践和重要的课程/建议,以制定有关网络安全教育和意识的高级计划。研究结果-尽管文献可以为指导教育和意识计划提供参考,但它可能并不总是能达到现实世界的计划。但是,现有的程序(例如本研究中探索的程序)具有巨大的潜力,但仍有改进的空间。这些领域中的每一个领域的知识都可以并且应该加以合并,以造福学术界和从业者社区。原创性/价值-该研究通过针对中小企业/中小型企业的网络安全教育和意识高级计划的大纲,为当前的研究做出了贡献。通过这项研究,研究了该领域的文献,并对正在进行的计划所面临的进步和挑战提出了见解。这些分析使我们能够为一项核心计划提出建议,该计划可以帮助改善针对中小企业/中小型企业的安全教育,意识和培训。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号