首页> 外文OA文献 >An Analysis of the Relationship between Security Information Technology Enhancements and Computer Security Breaches and Incidents
【2h】

An Analysis of the Relationship between Security Information Technology Enhancements and Computer Security Breaches and Incidents

机译:安全信息技术增强与计算机安全违规和事件之间的关系分析

摘要

Financial services institutions maintain large amounts of data that include both intellectual property and personally identifiable information for employees and customers. Due to the potential damage to individuals, government regulators hold institutions accountable for ensuring that personal data are protected and require reporting of data security breaches. No company wants a data breach, but finding a security incident or breach early in the attack cycle may decrease the damage or data loss a company experiences. In multiple high profile data breaches reported in major news stories over the past few years, there is a pattern of the adversary being inside the company’s network for months, and often law enforcement is the first to inform the company of the breach.The problem that was investigated in this case study was whether new information technology (IT) utilized by Fortune 500 financial services companies led to the changes in data security incidents and breaches. The goal of this dissertation is to gain a deeper understanding on how IT can increase awareness of a security incident or breach, and can also decrease security incidents and breaches. This dissertation also explores how threat information sharing increases awareness and decreases information security incidents and breaches. The objective of the study was to understand how changes in IT can influence an increase or decrease in data security breaches.This investigation was a case study of nine Fortune 500 financial services companies to understand what types of IT increase or decrease detection of security incidents and breaches. An increase in detecting and stopping a security incident or breach may have positive effects on the security of an enterprise. The longer a hacker has access to IT systems, the more entrenched they become and the more time the hacker has to locate data with high value. Time is of the essence to detect a compromise and react. The results of the case study showed that Fortune 500 companies utilized new IT that allowed them to improve their visibility of security incidents and breaches from months and years to hours and days.
机译:金融服务机构维护着大量数据,其中包括知识产权以及可供员工和客户使用的个人身份信息。由于可能对个人造成损害,政府监管机构要求机构负责确保个人数据受到保护,并要求报告数据安全漏洞。没有公司想要数据泄露,但是在攻击周期的早期发现安全事件或破坏可能会减少公司遭受的破坏或数据丢失。在过去几年的重大新闻中报道的多个引人注目的数据泄露事件中,有一种攻击者存在于公司网络中长达数月之久的一种模式,通常执法部门是第一个将泄露事件通知公司的人。在此案例研究中,调查了财富500强金融服务公司使用的新信息技术(IT)是否导致了数据安全事件和违规行为的变化。本文的目的是对IT如何增加对安全事件或违规的认识,以及如何减少安全事件和违规获得更深入的了解。本文还探讨了威胁信息共享如何提高认知度并减少信息安全事件和破坏。这项研究的目的是了解IT的变化如何影响数据安全漏洞的增加或减少。这项调查是对九家财富500强金融服务公司的案例研究,以了解哪种类型的IT可以增加或减少对安全事件的检测和发现。违反。检测和阻止安全事件或破坏的增加可能会对企业的安全产生积极影响。黑客访问IT系统的时间越长,它们变得越牢固,他们就越需要更多时间来定位具有高价值的数据。时间对于发现妥协和做出反应至关重要。案例研究的结果表明,《财富》 500强公司利用了新的IT技术,从几个月到几年到几小时到几天不等的时间里,他们可以提高对安全事件和安全漏洞的可见性。

著录项

  • 作者

    Betz Linda;

  • 作者单位
  • 年度 2016
  • 总页数
  • 原文格式 PDF
  • 正文语种
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号