...
首页> 外文期刊>Information & computer sceurity >It is not my job: exploring the disconnect between corporate security policies and actual security practices in SMEs
【24h】

It is not my job: exploring the disconnect between corporate security policies and actual security practices in SMEs

机译:这不是我的工作:探索中小企业中公司安全政策与实际安全实践之间的断开连接

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Purpose - This paper aims to present empirical results exemplifying challenges related to information security faced by small and medium enterprises (SMEs). It uses guidelines based on work system theory (WST) to frame the results, thereby illustrating why the mere existence of corporate security policies or general security training often is insufficient for establishing and maintaining information security. Design/methodology/approach - This research was designed to produce a better appreciation and understanding of potential issues or gaps in security practices in SMEs. The research team interviewed 187 employees of 39 SMEs in the UK All of those employees had access to sensitive information. Gathering information through interviews (instead of formal security documentation) made it possible to assess security practices from employees' point of view. Findings - Corporate policies that highlight information security are often disconnected from actual work practices and routines and often do not receive high priority in everyday work practices. A vast majority of the interviewed employees are not involved in risk assessment or in the development of security practices. Security practices remain an illusory activity in their real-world contexts. Research limitations/implications - This paper focuses only on closed-ended questions related to the following topics: awareness of existing security policy; information security practices and management and information security involvement. Practical implications - The empirical findings show that corporate information security policies in SMEs often are insufficient for maintaining security unless those policies are integrated with visible and recognized work practices in work systems that use or produce sensitive information. The interpretation based on WST provides guidelines for enhancing information system security. Originality/value - Beyond merely reporting empirical results, this research uses WST to interpret the results in a way that has direct implications for practitioners and for researchers.
机译:目的 - 本文旨在提出经验结果,体现了与中小型企业(SME)面临的信息安全有关的挑战。它使用基于工作系统理论(WST)的指南来构建结果,从而说明了为什么仅仅存在公司安全政策或一般安全培训,通常不足以建立和维护信息安全。设计/方法/方法 - 本研究旨在更好地理解和理解中小企业安全实践的潜在问题或差距。研究小组在英国采访了187名中小企业的187名员工,所有这些员工都可以访问敏感信息。通过访谈(而不是正式的安全文件)收集信息使得从员工的角度评估安全惯例成为可能。调查结果 - 强调信息安全性的公司政策通常与实际的工作实践和例行程序脱节,并且在日常工作实践中通常不会获得高度优先级。绝大多数接受采访的员工没有参与风险评估或安全实践的发展。在现实世界中,安全实践仍然是一项虚幻的活动。研究局限性/含义 - 本文仅着重于与以下主题相关的封闭问题:对现有安全政策的意识;信息安全实践,管理和信息安全参与。实际意义 - 经验发现表明,SME中的公司信息安全政策通常不足以维持安全性,除非这些政策与使用或生成敏感信息的工作系统中可见且公认的工作实践集成在一起。基于WST的解释提供了增强信息系统安全性的指南。原创性/价值 - 除了报告经验结果外,本研究还使用WST来解释结果,该结果直接对从业者和研究人员产生影响。

著录项

相似文献

  • 外文文献
  • 中文文献
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号