首页> 外文期刊>Information Technology, Learning, and Performance Journal >Mitigating Information Security Risks by Increasing User Security Awareness: A Case Study of an Information Security Awareness System
【24h】

Mitigating Information Security Risks by Increasing User Security Awareness: A Case Study of an Information Security Awareness System

机译:通过提高用户安全意识来减轻信息安全风险:信息安全意识系统的案例研究

获取原文
获取原文并翻译 | 示例
       

摘要

Organizations that lack security awareness can miss detecting many obvious security risks such as Trojans, phishing, viruses, and intellectual property theft in their daily activities. This lack of awareness can render sophisticated Internet security technologies useless and expose the organization to enormous risks. This paper adopts the systems development research methodology to investigate the security awareness needs of an insurance company that has an e-business presence. A pilot of a security awareness system was constructed for this investigative purpose. Various managers in the organization took part in the study. The pilot system was fine-tuned based on the usage experiences and feedback of participants. The findings indicate that the architecture of an information security awareness system needs to provide effective system management components that allow a system manager to customize the system interface in order to meet individual needs. In addition, the system itself needs to provide different functions such as an information portal, newsgroups, discussion forums, histories of security breach events, security awareness activities, and quality articles to facilitate the transmission of awareness concepts. The results of this study provide important lessons for organizations that plan to implement an effective information security awareness system.
机译:缺乏安全意识的组织可能会错过在日常活动中检测到许多明显的安全风险,例如特洛伊木马,网络钓鱼,病毒和知识产权盗窃。这种意识的缺乏会导致复杂的Internet安全技术无用,并使组织面临巨大的风险。本文采用系统开发研究方法来调查具有电子商务业务的保险公司的安全意识需求。为此,设计了一个安全意识系统的飞行员。该组织中的各种管理人员都参与了这项研究。根据使用经验和参与者的反馈对试点系统进行了微调。调查结果表明,信息安全意识系统的体系结构需要提供有效的系统管理组件,这些组件允许系统管理员自定义系统界面以满足个人需求。另外,系统本身需要提供不同的功能,例如信息门户,新闻组,讨论论坛,安全漏洞事件的历史记录,安全意识活动以及高质量的文章,以促进意识概念的传递。这项研究的结果为计划实施有效的信息安全意识系统的组织提供了重要的教训。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号