首页> 外文期刊>International Journal of Information Management >Reinforcing the security of corporate information resources: A critical review of the role of the acceptable use policy
【24h】

Reinforcing the security of corporate information resources: A critical review of the role of the acceptable use policy

机译:加强公司信息资源的安全性:严格审查可接受使用政策的作用

获取原文
获取原文并翻译 | 示例
           

摘要

Increasingly users are seen as the weak link in the chain, when it comes to the security of corporate information. Should the users of computer systems act in any inappropriate or insecure manner, then they may put their employers in danger of financial losses, information degradation or litigation, and themselves in danger of dismissal or prosecution. This is a particularly important concern for knowledge-intensive organisations, such as universities, as the effective conduct of their core teaching and research activities is becoming ever more reliant on the availability, integrity and accuracy of computer-based information resources. One increasingly important mechanism for reducing the occurrence of inappropriate behaviours, and in so doing, protecting corporate information, is through the formulation and application of a formal 'acceptable use policy (AUP). Whilst the AUP has attracted some academic interest, it has tended to be prescriptive and overly focussed on the role of the Internet, and there is relatively little empirical material that explicitly addresses the purpose, positioning or content of real acceptable use policies. The broad aim of the study, reported in this paper, is to fill this gap in the literature by critically examining the structure and composition of a sample of authentic policies - taken from the higher education sector - rather than simply making general prescriptions about what they ought to contain. There are two important conclusions to be drawn from this study: (1) the primary role of the AUP appears to be as a mechanism for dealing with unacceptable behaviour, rather than proactively promoting desirable and effective security behaviours, and (2) the wide variation found in the coverage and positioning of the reviewed policies is unlikely to be fostering a coherent approach to security management, across the higher education sector.
机译:在企业信息安全方面,越来越多的用户被视为链中的薄弱环节。如果计算机系统的用户以任何不适当或不安全的方式行事,则他们可能使雇主面临财务损失,信息降级或诉讼的危险,并有被解雇或起诉的危险。对于诸如大学这样的知识密集型组织来说,这尤其重要,因为其核心教学和研究活动的有效开展越来越依赖于计算机信息资源的可用性,完整性和准确性。减少不当行为的发生,从而保护公司信息的一种日益重要的机制是通过制定和应用正式的“可接受的使用政策”(AUP)。尽管AUP吸引了一些学术兴趣,但它往往是规范性的,并且过于关注Internet的作用,并且相对较少的经验材料可以明确地说明实际可接受使用政策的目的,定位或内容。本文报道的这项研究的广泛目标是,通过严格地检查来自高等教育部门的真实政策样本的结构和构成,来填补文献中的空白,而不是简单地就它们的内容制定一般性的规定。应该包含。从这项研究中可以得出两个重要的结论:(1)AUP的主要作用似乎是作为一种处理不可接受行为的机制,而不是积极促进可取和有效的安全行为;(2)差异很大在已审查政策的覆盖范围和定位中发现的问题,不太可能在整个高等教育部门中形成一种统一的安全管理方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号