首页> 外文OA文献 >Development of a Cybersecurity Skills Index: A Scenarios-Based, Hands-On Measure of Non-IT Professionalsu27 Cybersecurity Skills
【2h】

Development of a Cybersecurity Skills Index: A Scenarios-Based, Hands-On Measure of Non-IT Professionalsu27 Cybersecurity Skills

机译:网络安全技能指数的开发:一种基于场景的非IT专业人员动手措施 u27网络安全技能

摘要

Completing activities online are a part of everyday life, both professionally and personally. But, conducting daily operations, interacting, and sharing information on the Internet does not come without its risks as well as a potential for harm. Substantial financial and information losses for individuals, organizations, and governments are reported regularly due to vulnerabilities as well as breaches caused by insiders. Although advances in Information Technology (IT) have been significant over the past several decades when it comes to protection of corporate information systems (IS), human errors and social engineering appear to prevail in circumventing such IT protections. While most employees may have the best of intentions, without cybersecurity skills they represent the weakest link in an organization’s IS security. Skills are defined as the combination of knowledge, experience, and ability to do something well. Cybersecurity skills correspond to the skills surrounding the hardware and software required to execute IS security to mitigate cyber-attacks. The main goal of this research study was to develop a scenarios-based, hands-on measure of non-IT professionals’ cybersecurity skills. As opposed to IT professionals, end-users are one of the weakest links in the cybersecurity chain, due to their limited cybersecurity skills. Historically, non-IT professionals (i.e., office assistants, managers, executives) have access to sensitive data and represent 72% to 95% of cybersecurity threats to organizations. This study addressed the problem of threats to organizational IS due to vulnerabilities and breaches caused by employees. Current measures of cybersecurity skills of non-IT professionals are based on self-reported surveys and were found inaccurate. Prior IS and medical research found participants view scenarios as nonintrusive and unintimidating. Therefore, this research study utilized scenarios with observable hands-on tasks to measure and quantify cybersecurity skills of non-IT professionals. This study included developmental research with a sequential-exploratory approach to combine qualitative and quantitative data collection. To ensure validity and reliability of the Cybersecurity Skills Index (CSI), a panel of 18 subject matter experts (SMEs) reviewed the CSI following the Delphi expert methodology. The SMEs’ responses were incorporated into the development of an iPad application (app) prototype (MyCyberSkills™). Following the iPad app prototype development, eight SMEs provided feedback on the scenarios, tasks, and scoring of the app using the Delphi technique. Furthermore, pilot testing of the app was conducted by manually collecting and scoring the hands-on task performance of a group of 21 non-IT professionals. The manually collected data were compared to the app computed results to ensure reliability and validity. All revisions were incorporated into the prototype prior to the start of the empirical research phase. Once the iPad app prototype was completed and fully tested, the quantitative research phase used the prototype to collect data and document the results of the measure. Participants from multiple public organizations were asked to complete the scenarios-based, hands-on tasks as presented in the prototype. Following the pre-analysis data screening, this study used a combination of descriptive statistics and one-way analysis of variance (ANOVA) to address the research questions. Results from 188 participants indicate that educational level and experience using technology appear to be significant demographic variables when it comes to the level of cybersecurity skills demonstrated by non-IT professionals. Moreover, job function, hours accessing the Internet, or primary online activity did not appear to be significant variables when it comes to the level of cybersecurity skills of this population. This research validated that the CSI benchmarking index could be used to assess an individual’s cybersecurity skills level. As organizations continue to rely on the Internet for conducting their daily operations, understanding an employee’s cybersecurity skills level is critical to securing an organization’s IS. Moreover, the CSI operationalized into the MyCyberSkills™ iPad app prototype can be used to assess an organization’s employee’s demonstrated skills on cybersecurity tasks. Furthermore, assessing the cybersecurity skills levels of employees could provide an organization insight into what is needed to further mitigate threats due to vulnerabilities and breaches caused by employees. Discussions and implications for future research are provided.
机译:在线完成活动是专业和个人日常生活的一部分。但是,在Internet上进行日常操作,交互和共享信息并非没有风险和潜在危害。由于漏洞以及内部人员的违规行为,定期报告个人,组织和政府的重大财务和信息损失。尽管在过去的几十年中,信息技术(IT)的进步在保护公司信息系统(IS)方面取得了巨大的进步,但在规避此类IT保护方面,人为失误和社会工程学似乎占了上风。尽管大多数员工可能怀有最好的意图,但缺乏网络安全技能,却代表了组织IS安全中最薄弱的环节。技能是指知识,经验和做好事的能力的组合。网络安全技能与执行IS安全性以减轻网络攻击所需的软硬件技能相对应。这项研究的主要目的是针对非IT专业人员的网络安全技能,开发一种基于场景的动手方法。与IT专业人员相反,由于网络安全技能有限,最终用户是网络安全链中最薄弱的环节之一。从历史上看,非IT专业人员(即办公室助理,经理,高管)可以访问敏感数据,并构成对组织的网络安全威胁的72%至95%。这项研究解决了由于员工造成的漏洞和破坏而对组织IS构成威胁的问题。当前非IT专业人员的网络安全技能的衡量标准是根据自我报告的调查得出的,并不准确。先前的IS和医学研究发现,参与者认为场景是非侵入性的且没有威胁性。因此,本研究使用具有可观察到的动手任务的方案来衡量和量化非IT专业人员的网络安全技能。这项研究包括采用顺序探索性方法结合定性和定量数据收集的发展研究。为了确保网络安全技能指数(CSI)的有效性和可靠性,由18位主题专家(SME)组成的小组按照Delphi专家方法对CSI进行了审查。中小企业的回应被纳入了iPad应用程序(app)原型(MyCyber​​Skills™)的开发中。 iPad应用程序原型开发之后,八家中小型企业使用Delphi技术提供了有关应用程序的场景,任务和得分的反馈。此外,通过手动收集21个非IT专业人员的动手任务绩效并对其进行评分,对该应用程序进行了试点测试。将手动收集的数据与应用程序的计算结果进行比较,以确保可靠性和有效性。在经验研究阶段开始之前,所有修订均已纳入原型。 iPad应用程序原型完成并经过充分测试后,定量研究阶段便使用该原型收集数据并记录测量结果。来自多个公共组织的参与者被要求完成原型中介绍的基于场景的动手任务。在进行分析前的数据筛选之后,本研究结合了描述性统计数据和单向方差分析(ANOVA)来解决研究问题。 188名参与者的结果表明,就非IT专业人员所展示的网络安全技能水平而言,使用技术的教育水平和经验似乎是重要的人口变量。此外,就该人群的网络安全技能水平而言,工作职能,上网时间或主要在线活动似乎并不是重要的变量。这项研究验证了CSI基准指数可用于评估个人的网络安全技能水平。随着组织继续依靠Internet进行日常操作,了解员工的网络安全技能水平对于确保组织的IS至关重要。此外,可用于MyCyber​​Skills™iPad应用程序原型中的CSI可用于评估组织的员工在网络安全任务方面展示的技能。此外,评估员工的网络安全技能水平可以为组织提供深入了解进一步减轻由于员工造成的漏洞和破坏所造成的威胁所需的知识。提供了讨论和对未来研究的启示。

著录项

  • 作者

    Carlton Melissa;

  • 作者单位
  • 年度 2016
  • 总页数
  • 原文格式 PDF
  • 正文语种
  • 中图分类
  • 入库时间 2022-08-20 20:17:30

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号