首页> 外文期刊>Computers & Security >Validation of a socio-technical management process for optimising cybersecurity practices
【24h】

Validation of a socio-technical management process for optimising cybersecurity practices

机译:验证社会技术管理流程,以优化网络安全实践

获取原文
获取原文并翻译 | 示例
           

摘要

This study developed a socio-technical management process to optimise both technical and non-technical security measures to provide optimal, rather than adequate, enterprise security safeguards. The rationale was that over the last decade, studies have consistently shown that the human being remains the weakest link in the entire enterprise security chain. As a result, the majority of cyberattacks have resulted from human behaviour or error. Despite this, evidence suggests that many enterprises are still taking overly technocentric approaches to cybersecurity risk and this has increased the chances of missing the bigger picture. Thus, a mechanism to optimise both technical and non-technical security measures by identifying and closing socio-technical security gaps in existing enterprise security frameworks was required. The mechanism was derived from the literature and validated by industry practitioners where it was found that practitioners could categorise security controls into social (human included), technical and environmental dimensions. Through this, it was found that there were mainly non-technical (social and environmental dimensions) security gaps at practitioners' organisations. To further demonstrate how this security challenge can be identified and addressed, a desktop application of the management process was carried out on the COBIT 5 for Information Security framework. The results reveal the non-technical security gaps on COBIT 5 and the management process demonstrates how these could be closed and optimised. The importance of this study is to highlight that taking overly technocentric approaches to enterprise security risk does not yield significantly positive results in protecting assets. A new approach is required and the socio-technical management process is this paper's contribution to address that security challenge.
机译:本研究开发了一个社会技术管理过程,优化了技术和非技术安全措施,提供了最佳的,而不是充足的企业安全保障。理由是,在过去十年中,研究一直表明,人类仍然是整个企业安全链中最薄弱的联系。结果,大多数网络攻击是由人类行为或错误导致的。尽管如此,证据表明,许多企业仍在将过度技术的网络安全风险接近,这增加了缺少更大的画面的机会。因此,需要通过识别和关闭现有企业安全框架中的社会技术安全差距来优化技术和非技术安全措施的机制。该机制是从文献中得到的,由行业从业者验证,发现从业者可以将安全控制分类为社会(人类),技术和环境方面。通过这一点,发现从业者组织主要有非技术(社会和环境维度)安全差距。为了进一步演示如何识别和解决该安全挑战,在信息安全框架的Cobit 5上执行管理过程的桌面应用程序。结果揭示了Cobit 5上的非技术安全差距,管理流程展示了如何关闭和优化。本研究的重要性是强调,对企业安全风险的过度技术途径不会产生明显的积极成果在保护资产方面。需要一种新的方法,并且社会技术管理流程是本文对解决安全挑战的贡献。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号