Socio-technical systems cybersecurity framework

被引:32
|
作者
Malatji, Masike [1 ]
Von Solms, Sune [2 ]
Marnewick, Annlize [1 ]
机构
[1] Univ Johannesburg, Postgrad Sch Engn Management, Johannesburg, South Africa
[2] Univ Johannesburg, Dept Elect Engn Sci, Johannesburg, South Africa
关键词
Information security; Security; Modelling; SECURITY; INTERNET; MODEL; MATURITY; PRIVACY; THREAT; SAFETY; THINGS;
D O I
10.1108/ICS-03-2018-0031
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose This paper aims to identify and appropriately respond to any socio-technical gaps within organisational information and cybersecurity practices. This culminates in the equal emphasis of both the social, technical and environmental factors affecting security practices. Design/methodology/approach The socio-technical systems theory was used to develop a conceptual process model for analysing organisational practices in terms of their social, technical and environmental influence. The conceptual process model was then applied to specifically analyse some selected information and cybersecurity frameworks. The outcome of this exercise culminated in the design of a socio-technical systems cybersecurity framework that can be applied to any new or existing information and cybersecurity solutions in the organisation. A framework parameter to help continuously monitor the mutual alignment of the social, technical and environmental dimensions of the socio-technical systems cybersecurity framework was also introduced. Findings The results indicate a positive application of the socio-technical systems theory to the information and cybersecurity domain. In particular, the application of the conceptual process model is able to successfully categorise the selected information and cybersecurity practices into either social, technical or environmental practices. However, the validation of the socio-technical systems cybersecurity framework requires time and continuous monitoring in a real-life environment. Practical implications - This research is beneficial to chief security officers, risk managers, information technology managers, security professionals and academics. They will gain more knowledge and understanding about the need to highlight the equal importance of both the social, technical and environmental dimensions of information and cybersecurity. Further, the less emphasised dimension is posited to open an equal but mutual security vulnerability gap as the more emphasised dimension. Both dimensions must, therefore, equally and jointly be emphasised for optimal security performance in the organisation. Originality/value The application of socio-technical systems theory to the information and cybersecurity domain has not received much attention. In this regard, the research adds value to the information and cybersecurity studies where too much emphasis is placed on security software and hardware capabilities.
引用
收藏
页码:233 / 272
页数:40
相关论文
共 50 条
  • [1] A framework for the analysis of slack in socio-technical systems
    Saurin, Tarcisio Abreu
    Basso Werle, Natalia Jaeger
    [J]. RELIABILITY ENGINEERING & SYSTEM SAFETY, 2017, 167 : 439 - 451
  • [2] MIS implementation in schools: A systems socio-technical framework
    Telem, Moshe
    [J]. Computers and Education, 1996, 27 (02): : 85 - 93
  • [3] MIS implementation in schools: A systems socio-technical framework
    Telem, M
    [J]. COMPUTERS & EDUCATION, 1996, 27 (02) : 85 - 93
  • [4] Semi-Automating (or not) a Socio-Technical Method for Socio-Technical Systems
    Mendez, Christopher
    Hanson, Zoe Steine
    Oleson, Alannah
    Horvath, Amber
    Hill, Charles
    Hilderbrand, Claudia
    Sarma, Anita
    Burnett, Margaret
    [J]. 2018 IEEE SYMPOSIUM ON VISUAL LANGUAGES AND HUMAN-CENTRIC COMPUTING (VL/HCC), 2018, : 23 - 32
  • [5] Social Engineering Attacks: An Augmentation of the Socio-Technical Systems Framework
    Shozi, Nobubele Angel
    Modise, Mapule
    [J]. PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS-2015), 2015, : 305 - 312
  • [6] A multi-level socio-technical systems telecommuting framework
    Belanger, France
    Watson-Manheim, Mary Beth
    Swan, Bret R.
    [J]. BEHAVIOUR & INFORMATION TECHNOLOGY, 2013, 32 (12) : 1257 - 1279
  • [7] A socio-technical framework for quality assessment of computer information systems
    Palvia, SC
    Sharma, RS
    Conrath, DW
    [J]. INDUSTRIAL MANAGEMENT & DATA SYSTEMS, 2001, 101 (5-6) : 237 - 251
  • [8] A socio-technical framework for quality assessment of computer information systems
    Palvia, Shailendra C.
    Sharma, Ravi S.
    Conrath, David W.
    [J]. Industrial Management and Data Systems, 2001, 101 (5-6): : 237 - 251
  • [9] Cybersecurity for SMEs: Introducing the Human Element into Socio-technical Cybersecurity Risk Assessment
    Boletsis, Costas
    Halvorsrud, Ragnhild
    Pickering, J. Brian
    Phillips, Stephen
    Surridge, Mike
    [J]. IVAPP: PROCEEDINGS OF THE 16TH INTERNATIONAL JOINT CONFERENCE ON COMPUTER VISION, IMAGING AND COMPUTER GRAPHICS THEORY AND APPLICATIONS - VOL. 3: IVAPP, 2021, : 266 - 274
  • [10] A framework for model integration and holistic modelling of socio-technical systems
    Wu, Paul Pao-Yen
    Fookes, Clinton
    Pitchforth, Jegar
    Mengersen, Kerrie
    [J]. DECISION SUPPORT SYSTEMS, 2015, 71 : 14 - 27