Developing and implementing social engineering-prevention policies: a qualitative study

被引:0
|
作者
Steinmetz, Kevin F. [1 ]
Holt, Thomas J. [2 ]
Brewer, Christopher G. [3 ]
机构
[1] Kansas State Univ, Dept Sociol Anthropol & Social Work, Manhattan, KS 66506 USA
[2] Michigan State Univ, Sch Criminal Justice, E Lansing, MI USA
[3] Illinois State Univ, Dept Criminal Justice Sci, Normal, IL USA
基金
美国国家科学基金会;
关键词
Social engineering; Information security policy; Qualitative methods; Cybercrime; Policy development; INFORMATION SECURITY; TECHNOLOGY; MANAGEMENT; PERCEPTIONS; GOVERNANCE; BUSINESS; MODEL; STATE;
D O I
10.1057/s41284-023-00385-2
中图分类号
DF [法律]; D9 [法律];
学科分类号
0301 ;
摘要
Social engineering, or the use of deception to circumvent information security measures, has become a significant concern for organizations. Many organizations have implemented information security policies to mitigate the risks posed by social engineering attacks. This study uses a grounded theory-based approach to examine qualitative interviews with security auditors, IT security professionals, and social engineers (n = 54) to thematically catalog their insights on developing and supporting security policies. Results indicate that effective IT security policies are (1) properly communicated, (2) tested to find gaps in policy directives and their implementation, (3) buttressed by tools to facilitate good security decision-making among members, (4) written simply and concisely while being kept up-to-date, (5) supported through adequate staffing and expertise, (6) supported by organizational leadership, and (7) accompanied by an organizational structure which allows for policy to be overseen and implemented consistently.
引用
收藏
页码:599 / 617
页数:19
相关论文
共 50 条
  • [31] Barriers and facilitators to implementing cancer prevention clinical decision support in primary care: a qualitative study
    Melissa L. Harry
    Anjali R. Truitt
    Daniel M. Saman
    Hillary A. Henzler-Buckingham
    Clayton I. Allen
    Kayla M. Walton
    Heidi L. Ekstrom
    Patrick J. O’Connor
    JoAnn M. Sperl-Hillen
    Joseph A. Bianco
    Thomas E. Elliott
    BMC Health Services Research, 19
  • [32] Barriers and facilitators to implementing cancer prevention clinical decision support in primary care: a qualitative study
    Harry, Melissa L.
    Truitt, Anjali R.
    Saman, Daniel M.
    Henzler-Buckingham, Hillary A.
    Allen, Clayton I.
    Walton, Kayla M.
    Ekstrom, Heidi L.
    O'Connor, Patrick J.
    Sperl-Hillen, JoAnn M.
    Bianco, Joseph A.
    Elliott, Thomas E.
    BMC HEALTH SERVICES RESEARCH, 2019, 19 (1)
  • [33] Social exclusion, neoliberalism and resistance: The role of social workers in implementing social policies in Chile
    Munoz Arce, Gianinna
    Pantazis, Christina
    CRITICAL SOCIAL POLICY, 2019, 39 (01) : 127 - 146
  • [34] Extending social security: Policies for developing countries
    van Ginneken, W
    INTERNATIONAL LABOUR REVIEW, 2003, 142 (03) : 277 - +
  • [35] Developing and implementing an integrated delirium prevention system of care: a theory driven, participatory research study
    Mary Godfrey
    Jane Smith
    John Green
    Francine Cheater
    Sharon K Inouye
    John B Young
    BMC Health Services Research, 13
  • [36] Developing and implementing an integrated delirium prevention system of care: a theory driven, participatory research study
    Godfrey, Mary
    Smith, Jane
    Green, John
    Cheater, Francine
    Inouye, Sharon K.
    Young, John B.
    BMC HEALTH SERVICES RESEARCH, 2013, 13
  • [37] Challenges in implementing domestic funding policies for HIV prevention for key populations
    Talawat, S.
    Rahman, R.
    Panitchpakdi, P.
    JOURNAL OF THE INTERNATIONAL AIDS SOCIETY, 2018, 21 : 23 - 23
  • [38] Gender Differences to promote social policies of prevention
    Cavallari, B.
    Fanara, G.
    Mezzatesta, E.
    Sorrenti, L.
    Cucinotta, C.
    Nicotina, A.
    GENDER DIFFERENCE AND MENTAL HEALTH: ATTI DELLA CONFERENZA TEMATICA NAZIONALE DELLA SOCIETA ITALIANA DI PSICHIATRIA, 2012, : 181 - 184
  • [39] DEVELOPING AND IMPLEMENTING A BACK INJURY PREVENTION PROGRAM IN SMALL COMPANIES
    SELBY, NC
    OCCUPATIONAL MEDICINE-STATE OF THE ART REVIEWS, 1992, 7 (01): : 167 - 171
  • [40] Work in Progress - Developing and Implementing an Inverted Classroom for Engineering Statics
    Papadopoulos, Christopher
    Santiago-Roman, Aidsa
    Portela, Genock
    2010 IEEE FRONTIERS IN EDUCATION CONFERENCE (FIE), 2010,