首页> 外文OA文献 >THE SHAPING OF MANAGERS’ SECURITY OBJECTIVES THROUGH INFORMATION SECURITY AWARENESS TRAINING
【2h】

THE SHAPING OF MANAGERS’ SECURITY OBJECTIVES THROUGH INFORMATION SECURITY AWARENESS TRAINING

机译:通过信息安全意识培训来塑造管理者的安全目标

摘要

Information security research states that corporate security policy and information security training should be socio-technical in nature and that corporations should consider training as a primary method of protecting their information systems. However, information security policies and training are predominately technical in nature. In addition, managers creating security policies rely heavily on security guidelines, which are also technically oriented. This study created a series of information security training videos that were viewed by four groups of managers. One video discussed the socio-technical aspects of security, another discussed only the social aspects of security, the third detailed only the technical aspects of security, and the fourth was a control video unrelated to information security. Each group was shown the video, and after this viewing, each group’s values toward information security were ascertained and converted into security objectives following Keeney (1992)’s value-focused thinking approach. Each group’s list of security objectives were used as the input to Schmidt (1997)’s ranking Delphi methodology, which yielded a more concise and ranked list of security objectives. The results thus obtained, indicate that manager’s objectives towards information security are affected by the nature and scope of the information security training they receive. Information security policy based on each group’s value-based security objectives indicate that manager’s receiving socio-technical training would produce the strongest information security policy when analyzing the value-focused thinking list of security objectives. However, the quality of security policy decreases when analyzing the ranked Delphi list of security objectives, thus providing mixed results. The theoretical contribution of this research states that technically oriented information security training found in corporations today affects manager’s values and security objectives in a way that leads them to create and support technically oriented security policies, thus ignoring the social aspects of security. The practical contribution of this research states that managers should receive socio-technical information security training as a part of their regular job training, which would affect their values and lead to socio-technical information security policy based on the manager’s socio-technical security objectives. The methodological contribution of this research demonstrates the successful use of the value-focused thinking approach as the input to the ranking of the Delphi methodology.
机译:信息安全研究指出,公司安全策略和信息安全培训本质上应该是社会技术的,并且公司应该将培训视为保护其信息系统的主要方法。但是,信息安全策略和培训本质上是技术性的。此外,创建安全策略的管理人员在很大程度上依赖于安全指导,这些指导也以技术为导向。这项研究创建了一系列信息安全培训视频,四组管理人员均观看了这些视频。一个视频讨论了安全性的社会技术方面,另一个视频仅讨论了安全性的社会方面,第三个仅讨论了安全性的技术方面,第四个是与信息安全无关的控制视频。向每个小组展示了视频,并在观看之后确定了每个小组对信息安全的价值观,并根据Keeney(1992)的注重价值的思维方法将其转化为安全目标。每个小组的安全目标列表都用作Schmidt(1997)排名的Delphi方法的输入,该方法产生了更为简洁和排名更高的安全目标列表。如此获得的结果表明,经理对信息安全的目标受到他们所接受的信息安全培训的性质和范围的影响。基于每个小组基于价值的安全目标的信息安全策略表明,经理在分析以价值为重点的安全目标列表时,接受社会技术培训将产生最强的信息安全策略。但是,在分析排名的Delphi安全目标列表时,安全策略的质量会下降,因此提供了混合的结果。这项研究的理论贡献表明,如今在公司中发现的以技术为导向的信息安全培训会影响经理的价值观和安全目标,从而导致他们创建和支持以技术为导向的安全策略,从而忽略了安全性的社会方面。这项研究的实际贡献表明,管理人员应在日常工作培训中接受社会技术信息安全培训,这会影响他们的价值观,并根据管理者的社会技术安全目标制定社会技术信息安全政策。这项研究在方法论上的贡献表明,成功地使用了以价值为中心的思维方法作为Delphi方法论排名的输入。

著录项

  • 作者

    Harris Mark;

  • 作者单位
  • 年度 2010
  • 总页数
  • 原文格式 PDF
  • 正文语种
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号