首页> 外文OA文献 >A Risk-Driven Investment Model for Analysing Human Factors in Information Security
【2h】

A Risk-Driven Investment Model for Analysing Human Factors in Information Security

机译:用于分析信息安全中人为因素的风险驱动投资模型

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Information systems are of high importance in organisations because of the revolutionary industrial transformation undergone by digital and electronic platforms. A wide range of factors and issues forming the current business environments have created an unprecedented level of uncertainty and exposure to risks in all areas of strategic and operational activities in organisations including IT management and information security. Subsequently, securing these systems, which keep assets safe, serves organisational objectives. The Information Security System (ISS) is a process that organisations can adopt to achieve information security goals. It has gained the attention of academics, businesses, governments, security and IT professionals in recent years. Like any other system, the ISS is highly dependent on human factors as people are the primary concern of such systems and their roles should be taken into consideration. However, identifying reasoning and analysing human factors is a complex task. This is due to the fact that human factors are hugely subjective in nature and depend greatly on the specific organisational context. Every ISS development has unique demands both in terms of human factor specifications and organisational expectations. Developing an ISS often involves a notable proportion of risk due to the nature of technology and business demands; therefore, responding to these demands and technological challenges is critical. Furthermore, every business decision has inherent risk, and it is crucial to understand and make decisions based on the cost and potential value of that risk. Most research is solely concentrated upon the role of human factors in information security without addressing interrelated issues such as risk, cost and return of investment in security.udThe central focus and novelty of this research is to develop a risk-driven investment model within the security system framework. This model will support the analysis and reasoning of human factors in the information system development process. It contemplates risk, cost and the return of investment on security controls. The model will consider concepts from Requirements Engineering (RE), Security Tropos and organisational context. This model draws from the following theories and techniques: Socio-technical theory, Requirements Engineering (RE), SWOT analysis, Delphi Expert Panel technique and Force Field Analysis (FFA). The findings underline that the roles of human factors in ISSs are not being fully recognised or embedded in organisations and there is a lack of formalisation of main human factors in information security risk management processes. The study results should confirm that a diverse level of understanding of human factors impacts security systems. Security policies and guidelines do not reflect this reality. Moreover, information security has been perceived as being solely the domain of IT departments and not a collective responsibility, with the importance of the support of senior management ignored. A further key finding is the validation of all components of the Security Risk-Driven Model (RIDIM). Model components were found to be iterative and interdependent. The RIDIM model provides a significant opportunity to identify, assess and address these elements.udSome elements of ISSs offered in this research can be used to evaluate the role of human factors in enterprise information security; therefore, the research presents some aspects of computer science and information system features to introduce a solution for a business-oriented problem. The question of how to address the psychological dimensions of human factors related to information security would, however, be a rich topic of research on its own. The risk-driven investment model provides tangible methods and values of relevant variables that define the human factors, risk and return on investment that contribute to organisations’ information security systems. Such values and measures need to be interpreted in the context of organisational culture and the risk management model. Further research into the implementation of these measurements and evaluations for improving organisational risk management is required.
机译:信息系统在组织中非常重要,因为数字和电子平台经历了革命性的工业转型。形成当前业务环境的各种因素和问题已经在组织的战略和运营活动的所有领域(包括IT管理和信息安全)中创造了前所未有的不确定性和风险敞口。随后,保护这些可保护资产安全的系统可为组织目标服务。信息安全系统(ISS)是组织可以用来实现信息安全目标的过程。近年来,它已经引起了学术界,企业,政府,安全和IT专业人员的关注。像其他任何系统一样,国际空间站高度依赖人为因素,因为人们是此类系统的主要关注点,应考虑其作用。但是,识别推理和分析人为因素是一项复杂的任务。这是由于以下事实:人为因素本质上是非常主观的,并且在很大程度上取决于特定的组织环境。无论是在人为因素规范还是在组织期望方面,每个ISS的发展都具有独特的要求。由于技术和业务需求的性质,发展国际空间站通常涉及相当大的风险。因此,应对这些需求和技术挑战至关重要。此外,每个业务决策都有内在的风险,因此,了解和基于该风险的成本和潜在价值做出决策至关重要。大多数研究仅集中于人为因素在信息安全中的作用,而没有解决诸如安全性方面的风险,成本和回报等相互关联的问题。 ud本研究的重点和新颖性在于在企业内部开发风险驱动的投资模型。安全系统框架。该模型将支持信息系统开发过程中人为因素的分析和推理。它考虑了风险,成本和安全控制方面的投资回报。该模型将考虑来自需求工程(RE),安全性Tropos和组织环境的概念。该模型基于以下理论和技术:社会技术理论,需求工程(RE),SWOT分析,Delphi专家小组技术和力场分析(FFA)。研究结果强调,人为因素在国际空间站中的作用尚未得到充分认识或嵌入组织中,并且在信息安全风险管理流程中缺乏主要人为因素的形式化。研究结果应确认对人为因素的不同理解会影响安全系统。安全策略和准则不能反映这一现实。此外,人们已经将信息安全视为IT部门的唯一职责,而不是集体责任,而忽略了高层管理人员支持的重要性。另一个关键发现是验证安全风险驱动模型(RIDIM)的所有组件。发现模型组件是迭代的并且相互依赖。 Rudim模型提供了识别,评估和解决这些要素的重要机会。 ud本研究中提供的ISS的某些要素可用于评估人为因素在企业信息安全中的作用;因此,本研究提出了计算机科学和信息系统功能的某些方面,以介绍针对业务问题的解决方案。然而,如何解决与信息安全有关的人为因素的心理层面的问题,将是一个单独的研究课题。风险驱动的投资模型提供了相关变量的有形方法和价值,这些变量和值定义了有助于组织的信息安全系统的人为因素,风险和投资回报。这些价值和措施需要在组织文化和风险管理模型的背景下进行解释。需要对这些度量和评估的实施进行进一步研究,以改善组织风险管理。

著录项

  • 作者

    Mortazavi-Alavi Reza;

  • 作者单位
  • 年度 2016
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号