The Human Element of Information Security

被引:9
|
作者
Thompson, Hugh
机构
关键词
information security; security; security architecture; social engineering;
D O I
10.1109/MSP.2012.161
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information security has long hinged on trusted insiders' ability to make good decisions. However, modifying human behavior through training is difficult; some battle-worn security executives might even dismiss it as impossible. Although foundational controls such as antivirus, data leak protection, and firewalls are important, they're far from sufficient. The sharp rise in 'knowability' of people at a distance raises an important question for the information security industry about the automation of personalized attacks: what happens when the marginal cost of launching a convincing personalized attack starts to approach 0 Today, most security controls are ignorant of rich historical data about the person they're tasked with protecting. As the cost for attackers to personalize their attacks goes down, our zeal in building technology to personalize defense must rise. This article explores our industry's need to embrace security's human element. © 2003-2012 IEEE.
引用
收藏
页码:32 / 35
页数:4
相关论文
共 50 条
  • [1] Trust: An element of information security
    Flowerday, Stephen
    von Solms, Rossouw
    [J]. SECURITY AND PRIVACY IN DYNAMIC ENVIRONMENTS, 2006, 201 : 87 - +
  • [2] Holistic security: The integration of information and physical security as an element of homeland security
    Hamilton, Caroline
    [J]. Computer Security Journal, 2003, 19 (01): : 35 - 40
  • [3] INFORMATION POLICY AS AN ELEMENT OF ENFORCING THE STATE'S INFORMATION SECURITY
    Britchenko, Igor
    Hladchenko, Svitlana
    Viktorova, Lesta
    Pronoza, Inna
    Ulianova, Kateryna
    [J]. AD ALTA-JOURNAL OF INTERDISCIPLINARY RESEARCH, 2022, 12 (01): : 110 - 114
  • [4] SECURITY IN HUMAN INFORMATION ASSETS
    Mario Cadavid-Aguirre, Jorge
    [J]. REVISTA DIGITAL LAMPSAKOS, 2013, (10): : 17 - 19
  • [5] Human aspects of information security
    Furnell, Steven
    Clarke, Nathan
    [J]. INFORMATION AND COMPUTER SECURITY, 2016, 24 (02) : 138 - 138
  • [6] Information systems security and human behaviour
    Trcek, Denis
    Trobec, Roman
    Pavesic, Nikola
    Tasic, J. F.
    [J]. BEHAVIOUR & INFORMATION TECHNOLOGY, 2007, 26 (02) : 113 - 118
  • [7] Information Security as a Guarantee for Human Rights
    Tulikov, Alexey
    [J]. PRAVO-ZHURNAL VYSSHEI SHKOLY EKONOMIKI, 2015, (02): : 50 - 60
  • [8] Information Security management: A human challenge?
    Department of Informatics and Sensors, Cranfield University, Swindon, SN6 8LA, United Kingdom
    [J]. Inf Secur Tech Rep, 2008, 4 (195-201):
  • [9] The Human Factor in Managing the Security of Information
    Wisniewska, Malgorzata
    Wisniewski, Zbigniew
    Szaniawska, Katarzyna
    Lehmann, Michal
    [J]. ADVANCES IN HUMAN FACTORS IN CYBERSECURITY, 2020, 960 : 38 - 47
  • [10] Towards the Human Information Security Firewall
    von Solms, Rossouw
    Warren, Matthew
    [J]. INTERNATIONAL JOURNAL OF CYBER WARFARE AND TERRORISM, 2011, 1 (02) : 10 - 17