首页> 外文OA文献 >An information security risk-driven investment model for analysing human factors
【2h】

An information security risk-driven investment model for analysing human factors

机译:信息安全风险驱动的人为因素分析投资模型

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Modern organisational structure and risk management model are characterised by a wide\udrange of forces including the role of human factors which combine to create an\udunprecedented level of uncertainty and exposure to information security risk, investment and\uddecision making process. Developing a risk-driven investment model for information security\udsystems with consideration of subjective nature of critical human factors, is a challenging\udtask. The overall success of an information security system depends on analysis of the risks\udand threats so that appropriate protection mechanism can be in place to protect them.\udHowever, lack of appropriate analysis of such dependencies and understanding potentially\udresults in information security systems to fail or to fully achieve their that depend on them.\udExisting literature does not provide adequate guidelines for a systematic process or an\udappropriate modelling language to support such analysis. This paper fills this gap by\udintroducing a process that allows information security managers to capture possible riskinvestment\udrelationships and to reason about them. The process is supported by a modelling\udlanguage based on a set of concepts relating to trust and control and secure tropos and\udrequirements engineering. In order to demonstrate the applicability and usefulness of the\udapproach a descriptive example from an UK organisation is used.\udKeywords: Information Security (IS), Information Security Risk-Driven Investment Model (RIDIM),\udRisk, Social Engineering Attacks (SEAs), Security Investment (SI), Return On Investment in\udInformation Security (ROISI).
机译:现代组织结构和风险管理模型的特征是力量范围广,包括人为因素的作用,这些因素共同造成了前所未有的不确定性,并暴露于信息安全风险,投资和决策过程中。考虑到关键的人为因素的主观性,为信息安全\ udsystem开发风险驱动的投资模型是一项具有挑战性的任务。信息安全系统的总体成功取决于对风险\ udand威胁的分析,以便可以采用适当的保护机制来保护它们。\ ud但是,缺乏对此类依存关系的适当分析以及对信息安全系统的潜在了解/了解失败或无法完全实现依赖它们的结果。\ ud现有文献没有为系统化过程或适当的建模语言提供足够的指导以支持此类分析。本文通过\介绍一种使信息安全管理人员能够捕获可能的风险投资\非关系并对其进行推理的过程来填补这一空白。基于一组与信任和控制以及安全对等和非需求工程有关的概念的建模\语言支持该过程。为了证明该方法的适用性和实用性,使用了来自英国组织的描述性示例。\ ud关键字:信息安全(IS),信息安全风险驱动的投资模型(RIDIM),\ udRisk,社会工程攻击(SEA) ),安全投资(SI),\ udInformation Security(ROISI)的投资回报率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号