首页> 外文期刊>Kybernetes: The International Journal of Systems & Cybernetics >Using systems dynamics for human resources management in information systems security
【24h】

Using systems dynamics for human resources management in information systems security

机译:使用系统动力学来管理信息系统安全中的人力资源

获取原文
获取原文并翻译 | 示例
           

摘要

Purpose - To enable quantitative and qualitative modelling of information systems security management that takes into account technology and human factor. Design/methodology/approach - The approach is based on systems dynamics and it is done in two phases. In the first phase two basic qualitative models are developed, while in the second phase a possibility to further develop them into quantitative models is studied. Findings - Appropriate approach to IS security management requires addressing "hard" and "soft" factors. Further, to enable quantitative study of such systems, which are highly non-linear, exact analytical (mathematically rigorous) treatment is close to impossible. Thus, computer simulations have to be used. One appropriate methodological answer to the above requirements is systems (business) dynamics. Research limitations/implications - Research limitations are partially related to system dynamics, which operates on an aggregates level. This prevents or makes harder study of phenomena at the micro level, from where the above-mentioned aggregates emerge. Further, many sub-areas need further standardisation to enable more realistic simulations - one such case is security policy standardisation and quantification. Similar holds true for threats/vulnerabilities and related taxonomies. Practical implications - The research presents one of first steps in the direction that could provide quantitative models for effective IS security policy management in organisations. Originality/value - The research presents two models, one for risk management and the other, which is a generic model that identifies basic variables that have to be addressed for IS security management. Further, findings can be used for security awareness courses.
机译:目的-在考虑技术和人为因素的情况下,对信息系统安全管理进行定量和定性建模。设计/方法/方法-该方法基于系统动力学,分两个阶段完成。在第一阶段,开发了两个基本的定性模型,而在第二阶段,研究了将其进一步发展为定量模型的可能性。发现-IS安全管理的适当方法需要解决“硬”和“软”因素。此外,为了能够对高度非线性的此类系统进行定量研究,几乎不可能进行精确的分析(数学上严格的)处理。因此,必须使用计算机模拟。对上述要求的一种适当的方法论答案是系统(业务)动态。研究局限性/含义-研究局限性部分与系统动态有关,系统动态在聚合级别上运行。这会阻止或更难于微观层面研究上述聚集体从那里出现的现象。此外,许多子区域需要进一步标准化以实现更逼真的仿真-一种情况是安全策略标准化和量化。威胁/漏洞和相关分类法也是如此。实际意义-研究提出了该方向的第一步,该方向可以为组织中有效的IS安全策略管理提供定量模型。原创性/价值-研究提出了两种模型,一种用于风险管理,另一种用于识别IS安全管理必须解决的基本变量的通用模型。此外,调查结果可用于安全意识课程。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号