Developing and implementing social engineering-prevention policies: a qualitative study

被引:0
|
作者
Steinmetz, Kevin F. [1 ]
Holt, Thomas J. [2 ]
Brewer, Christopher G. [3 ]
机构
[1] Kansas State Univ, Dept Sociol Anthropol & Social Work, Manhattan, KS 66506 USA
[2] Michigan State Univ, Sch Criminal Justice, E Lansing, MI USA
[3] Illinois State Univ, Dept Criminal Justice Sci, Normal, IL USA
基金
美国国家科学基金会;
关键词
Social engineering; Information security policy; Qualitative methods; Cybercrime; Policy development; INFORMATION SECURITY; TECHNOLOGY; MANAGEMENT; PERCEPTIONS; GOVERNANCE; BUSINESS; MODEL; STATE;
D O I
10.1057/s41284-023-00385-2
中图分类号
DF [法律]; D9 [法律];
学科分类号
0301 ;
摘要
Social engineering, or the use of deception to circumvent information security measures, has become a significant concern for organizations. Many organizations have implemented information security policies to mitigate the risks posed by social engineering attacks. This study uses a grounded theory-based approach to examine qualitative interviews with security auditors, IT security professionals, and social engineers (n = 54) to thematically catalog their insights on developing and supporting security policies. Results indicate that effective IT security policies are (1) properly communicated, (2) tested to find gaps in policy directives and their implementation, (3) buttressed by tools to facilitate good security decision-making among members, (4) written simply and concisely while being kept up-to-date, (5) supported through adequate staffing and expertise, (6) supported by organizational leadership, and (7) accompanied by an organizational structure which allows for policy to be overseen and implemented consistently.
引用
收藏
页码:599 / 617
页数:19
相关论文
共 50 条
  • [1] Implementing healthy food policies in health services: A qualitative study
    Boelsen-Robinson, Tara
    Blake, Miranda R.
    Backholer, Kathryn
    Hettiarachchi, Janitha
    Palermo, Claire
    Peeters, Anna
    NUTRITION & DIETETICS, 2019, 76 (03) : 336 - 343
  • [2] UNDERSTANDING THE PROCESS OF DEVELOPING AND IMPLEMENTING CHRONIC DISEASE POLICIES IN THE CARIBBEAN REGION: A QUALITATIVE POLICY ANALYSIS
    Guell, C.
    Murphy, M. M.
    Samuels, T. A.
    Bishop, L.
    Unwin, N.
    JOURNAL OF EPIDEMIOLOGY AND COMMUNITY HEALTH, 2017, 71 : A37 - A37
  • [3] Developing and implementing IS: a case study analysis in social services
    Riley, L
    Smith, G
    JOURNAL OF INFORMATION TECHNOLOGY, 1997, 12 (04) : 305 - 321
  • [4] Management Policies for the Prevention Technique of Social Engineering (SoE) Attacks in the Organization
    Khidzir, Nik Zulkarnaen
    Ahmed, Shekh Abdullah-Al-Musa
    Guan, Tan Tse
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2019, 19 (10): : 78 - 82
  • [5] A qualitative study of facilitators and barriers to implementing worksite policies that support physical activity
    Bailey, Maryanne M.
    Coller, Rachel K.
    Porter, Keshia M. Pollack
    BMC PUBLIC HEALTH, 2018, 18
  • [6] A qualitative study of facilitators and barriers to implementing worksite policies that support physical activity
    Maryanne M Bailey
    Rachel K Coller
    Keshia M Pollack Porter
    BMC Public Health, 18
  • [7] Risk Management Should Play a Stronger Role in Developing and Implementing Social Responsibility Policies for Organizations
    Thekdi, Shital A.
    RISK ANALYSIS, 2016, 36 (05) : 870 - 873
  • [8] Implementing a Multicomponent School-Based Obesity Prevention Intervention: A Qualitative Study
    Greaney, Mary L.
    Hardwick, Cary K.
    Spadano-Gasbarro, Jennifer L.
    Mezgebu, Solomon
    Horan, Christine M.
    Schlotterbeck, Sara
    Austin, S. Bryn
    Peterson, Karen E.
    JOURNAL OF NUTRITION EDUCATION AND BEHAVIOR, 2014, 46 (06) : 576 - 582
  • [9] Developing and implementing work-family policies for faculty
    Sullivan, B
    Hollenshead, C
    Smith, G
    ACADEME-BULLETIN OF THE AAUP, 2004, 90 (06): : 24 - 27
  • [10] Implementing and evaluating crime prevention and control programs and policies
    Delbert S. Elliott
    Crime, Law and Social Change, 1997, 28 : 287 - 310