...
首页> 外文期刊>Information & computer security >It is not my job: exploring the disconnect between corporate security policies and actual security practices in SMEs
【24h】

It is not my job: exploring the disconnect between corporate security policies and actual security practices in SMEs

机译:这不是我的工作:探索公司安全政策与中小企业实际安全实践之间的断开连接

获取原文
获取原文并翻译 | 示例
           

摘要

Purpose - This paper aims to present empirical results exemplifying challenges related to information security faced by small and medium enterprises (SMEs). It uses guidelines based on work system theory (WST) to frame the results, thereby illustrating why the mere existence of corporate security policies or general security training often is insufficient for establishing and maintaining information security. Design/methodology/approach - This research was designed to produce a better appreciation and understanding of potential issues or gaps in security practices in SMEs. The research team interviewed 187 employees of 39 SMEs in the UK All of those employees had access to sensitive information. Gathering information through interviews (instead of formal security documentation) made it possible to assess security practices from employees' point of view. Findings - Corporate policies that highlight information security are often disconnected from actual work practices and routines and often do not receive high priority in everyday work practices. A vast majority of the interviewed employees are not involved in risk assessment or in the development of security practices. Security practices remain an illusory activity in their real-world contexts. Research limitations/implications - This paper focuses only on closed-ended questions related to the following topics: awareness of existing security policy; information security practices and management and information security involvement. Practical implications - The empirical findings show that corporate information security policies in SMEs often are insufficient for maintaining security unless those policies are integrated with visible and recognized work practices in work systems that use or produce sensitive information. The interpretation based on WST provides guidelines for enhancing information system security. Originality/value - Beyond merely reporting empirical results, this research uses WST to interpret the results in a way that has direct implications for practitioners and for researchers.
机译:目的 - 本文旨在展示实证结果,示出了中小企业面临的信息安全相关的挑战(中小企业)。它使用基于工作系统理论(WST)的指南来框架结果,从而说明了仅仅存在企业安全政策或一般安全培训的原因,通常不足以建立和维护信息安全。设计/方法论/方法 - 本研究旨在更好地欣赏和了解中小企业安全实践中的潜在问题或差距。研究团队在英国采访了187名员工39名中小企业,所有这些员工都可以获得敏感信息。通过访谈收集信息(而不是正式的安全文件)使得可以从员工的角度评估安全实践。调查结果 - 突出信息安全的公司政策通常与实际工作实践和例程断开连接,并且通常不会在日常工作实践中获得高优先级。绝大多数采访的员工不参与风险评估或在安全实践的发展中。安全实践仍然是他们真实世界的虚幻活动。研究限制/含义 - 本文仅关注与以下主题相关的封闭式问题:现有安全政策的认识;信息安全实践和管理和信息安全参与。实际意义 - 实证研究结果表明,中小企业的企业信息安全政策通常不足以维护安全性,除非这些策略与使用或产生敏感信息的工作系统中的可见和公认的工作实践集成。基于WST的解释提供了提高信息系统安全性的指导。原创性/值 - 超越仅仅是报告的经验结果,本研究使用WST以对从业者和研究人员的直接影响的方式解释结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号