首页> 外文OA文献 >An information security awareness capability model (ISACM)
【2h】

An information security awareness capability model (ISACM)

机译:信息安全意识能力模型(ISACM)

摘要

A lack of information security awareness within some parts of society as well as some organisations continues to exist today. Whilst we have emerged from the threats of late 1990s of virus such as Code Red and Melissa, through to the phishing emails of the mid 2000’s and the financial damage some such as the Nigerian scam caused, we continue to react poorly to new threats such as demanding money via SMS with a promise of death to those that won’t pay. So is this lack of awareness translating into problems within the workforce? There is often a lack of knowledge as to what is an appropriate level of awareness for information security controls across an organisation. This paper presents the development of a theoretical framework and model that combines aspects of information security best practice standards as presented in ISO/IEC 27002 with theories of Situation Awareness. The resultant model is an information security awareness capability model (ISACM). A preliminary survey is being used to develop the Awareness Importance element of the model and will leverage the opinions of information security professionals. A subsequent survey is also being developed to measure the Awareness Capability element of the model. This will present a number of scenarios with a series of cascading questions that test Level 1 situation awareness (perception), Level 2 situation awareness (comprehension) and finally Level 3 situation awareness (projection).
机译:如今,社会某些部分以及某些组织缺乏信息安全意识。尽管我们已经从1990年代后期的病毒(如Red Red和Melissa)的威胁中脱颖而出,再到2000年代中期的网络钓鱼电子邮件以及某些诸如尼日利亚骗局等造成的经济损失,但我们仍然对新威胁(例如,通过短信索要钱,并向那些不会付钱的人致死。那么,这种缺乏意识会转化为劳动力内部的问题吗?通常缺乏对整个组织中的信息安全控制的适当认识水平的知识。本文介绍了理论框架和模型的发展,该模型结合了ISO / IEC 27002中提出的信息安全最佳实践标准的各个方面以及情境意识理论。结果模型是信息安全意识能力模型(ISACM)。初步调查正在用于开发模型的“重要性”元素,并将利用信息安全专业人员的意见。后续调查也正在开发中,以测量模型的“感知能力”元素。这将提出一系列带有一系列级联问题的场景,以测试1级情景意识(感知),2级情景意识(理解)以及最终3级情景意识(投影)。

著录项

  • 作者

    Poepjes Robert; Lane Michael;

  • 作者单位
  • 年度 2012
  • 总页数
  • 原文格式 PDF
  • 正文语种 {"code":"en","name":"English","id":9}
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号