Developing and implementing social engineering-prevention policies: a qualitative study

被引:0
|
作者
Steinmetz, Kevin F. [1 ]
Holt, Thomas J. [2 ]
Brewer, Christopher G. [3 ]
机构
[1] Kansas State Univ, Dept Sociol Anthropol & Social Work, Manhattan, KS 66506 USA
[2] Michigan State Univ, Sch Criminal Justice, E Lansing, MI USA
[3] Illinois State Univ, Dept Criminal Justice Sci, Normal, IL USA
基金
美国国家科学基金会;
关键词
Social engineering; Information security policy; Qualitative methods; Cybercrime; Policy development; INFORMATION SECURITY; TECHNOLOGY; MANAGEMENT; PERCEPTIONS; GOVERNANCE; BUSINESS; MODEL; STATE;
D O I
10.1057/s41284-023-00385-2
中图分类号
DF [法律]; D9 [法律];
学科分类号
0301 ;
摘要
Social engineering, or the use of deception to circumvent information security measures, has become a significant concern for organizations. Many organizations have implemented information security policies to mitigate the risks posed by social engineering attacks. This study uses a grounded theory-based approach to examine qualitative interviews with security auditors, IT security professionals, and social engineers (n = 54) to thematically catalog their insights on developing and supporting security policies. Results indicate that effective IT security policies are (1) properly communicated, (2) tested to find gaps in policy directives and their implementation, (3) buttressed by tools to facilitate good security decision-making among members, (4) written simply and concisely while being kept up-to-date, (5) supported through adequate staffing and expertise, (6) supported by organizational leadership, and (7) accompanied by an organizational structure which allows for policy to be overseen and implemented consistently.
引用
收藏
页码:599 / 617
页数:19
相关论文
共 50 条
  • [41] Implementing Local Policies for Case Study Sulina
    Nichersu, Iuliana
    Nichersu, Iulian
    Mierla, Marian
    Marin, Eugenia
    Trifanov, Cristian
    GLOBAL CONGRESS ON ICM: LESSONS LEARNED TO ADDRESS NEW CHALLENGES, VOLS. 1 AND 2, 2013, : 47 - 58
  • [42] Developing a Social-Engineering Course
    Ngambeki, Ida
    Ahluwalia, Grusha
    Ansari, Subia
    Li, Minglu
    Arul, Glaris Lancia Raja
    2021 IEEE FRONTIERS IN EDUCATION CONFERENCE (FIE 2021), 2021,
  • [43] Social engineering of the Internet in developing areas
    Shrum, W
    EDUCATION AND THE KNOWLEDGE SOCIETY: INFORMATION TECHNOLOGY SUPPORTING HUMAN DEVELOPMENT, 2005, : 213 - 221
  • [44] Developing a text-message library for tobacco prevention among adolescents: A qualitative study
    Khalil, Georges Elias
    McLean, David
    Ramirez, Erica
    Mihaj, Paris Piere
    Zhao, Bairu
    Dhar, Biswadeep
    Khan, Meerah
    PLOS ONE, 2024, 19 (01):
  • [45] A qualitative study of design stakeholders' views of developing and implementing a registry-based learning health system
    Dixon-Woods, Mary
    Campbell, Anne
    Chang, Trillium
    Martin, Graham
    Georgiadis, Alexandros
    Heney, Veronica
    Chew, Sarah
    Van Citters, Aricca
    Sabadosa, Kathryn A.
    Nelson, Eugene C.
    IMPLEMENTATION SCIENCE, 2020, 15 (01)
  • [46] A qualitative study of design stakeholders’ views of developing and implementing a registry-based learning health system
    Mary Dixon-Woods
    Anne Campbell
    Trillium Chang
    Graham Martin
    Alexandros Georgiadis
    Veronica Heney
    Sarah Chew
    Aricca Van Citters
    Kathryn A. Sabadosa
    Eugene C. Nelson
    Implementation Science, 15
  • [47] Implementing a Digital Depression Prevention Program in Australian Secondary Schools: Cross-Sectional Qualitative Study
    Beames, Joanne R.
    Werner-Seidler, Aliza
    Hodgins, Michael
    Brown, Lyndsay
    Fujimoto, Hiroko
    Bartholomew, Alexandra
    Maston, Kate
    Huckvale, Kit
    Zbukvic, Isabel
    Torok, Michelle
    Christensen, Helen
    Batterham, Philip J.
    Calear, Alison L.
    Lingam, Raghu
    Boydell, Katherine M.
    JMIR PEDIATRICS AND PARENTING, 2023, 6
  • [48] Community service provider perceptions of implementing older adult fall prevention in Ontario, Canada: a qualitative study
    Dykeman, Catherine S.
    Markle-Reid, Maureen F.
    Boratto, Lorna J.
    Bowes, Chris
    Gagne, Helene
    McGugan, Jennifer L.
    Orr-Shaw, Sarah
    BMC GERIATRICS, 2018, 18
  • [49] Community service provider perceptions of implementing older adult fall prevention in Ontario, Canada: a qualitative study
    Catherine S. Dykeman
    Maureen F. Markle-Reid
    Lorna J. Boratto
    Chris Bowes
    Hélène Gagné
    Jennifer L. McGugan
    Sarah Orr-Shaw
    BMC Geriatrics, 18
  • [50] Experiences of doctors and nurses implementing nurse-delivered cardiovascular prevention in primary care: a qualitative study
    Voogdt-Pruis, Helene R.
    Beusmans, George H. M. I.
    Gorgels, Anton P. M.
    van Ree, Jan W.
    JOURNAL OF ADVANCED NURSING, 2011, 67 (08) : 1758 - 1766