首页> 外文OA文献 >Fostering information security culture through intergrating theory and technology
【2h】

Fostering information security culture through intergrating theory and technology

机译:通过理论与技术的结合培育信息安全文化

摘要

Today information can be seen as a basic commodity that is crucial to the continuous well-being of modern organizations. Many modern organizations will be unable to do business without access to their information resources. It is therefor of vital importance for organizations to ensure that their infor- mation resources are adequately protected against both internal and external threats. This protection of information resources is known as information security and is, to a large extent, dependent on the behavior of humans in the organization. Humans, at various levels in the organization, play vital roles in the pro- cesses that secure organizational information resources. Many of the prob- lems experienced in information security can be directly contributed to the humans involved in the process. Employees, either intentionally or through negligence, often due to a lack of knowledge, can be seen as the greatest threat to information security. Addressing this human factor in information security is the primary focus of this thesis. The majority of current approaches to dealing with the human factors in information security acknowledge the need to foster an information security culture in the organization. However, very few current approaches attempt to adjust the "generic" model(s) used to define organizational culture to be specific to the needs of information security. This thesis firstly proposes, and argues, such an adapted conceptual model which aims to improve the understanding of what an information security culture is. The thesis secondly focuses on the underlying role that information security educational programs play in the fostering of an organizational information security culture. It is argued that many current information security edu- cational programs are not based on sound pedagogical theory. The use of learning taxonomies during the design of information security educational programs is proposed as a possible way to improve the pedagogical rigor of such programs. The thesis also argues in favor of the use of blended and/or e-learning approaches for the delivery of information security educational content. Finally, this thesis provides a detailed overview demonstrating how the various elements contributed by the thesis integrates into existing trans- formative change management processes for the fostering of an organizational information security culture.
机译:今天,信息可以被视为对现代组织的持续福祉至关重要的基本商品。如果不访问其信息资源,许多现代组织将无法开展业务。因此,对于组织而言,至关重要的是确保充分保护其信息资源免受内部和外部威胁。信息资源的这种保护被称为信息安全,并且在很大程度上取决于组织中人员的行为。组织中各个级别的人员在确保组织信息资源安全的过程中都起着至关重要的作用。信息安全中遇到的许多问题都可以直接带给参与该过程的人员。经常由于缺乏知识而有意或无意地将员工视为对信息安全的最大威胁。解决信息安全中的人为因素是本文的重点。当前处理信息安全中人为因素的大多数方法都承认有必要在组织中培养信息安全文化。但是,目前很少有方法尝试调整用于定义组织文化的“通用”模型,使其特定于信息安全的需求。本文首先提出并提出了这样一种适应性概念模型,旨在增进对信息安全文化的理解。其次,本文着眼于信息安全教育计划在组织信息安全文化的培养中所起的潜在作用。有人认为,当前许多信息安全教育计划都不基于合理的教学理论。建议在信息安全教育计划的设计中使用学习分类法,以提高此类计划的教学严格性。本文还主张使用混合和/或电子学习方法来交付信息安全教育内容。最后,本文提供了详细的概述,说明了本文所贡献的各种要素如何融入现有的变革性变更管理流程中,以促进组织信息安全文化的发展。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号