Information security management: An information security retrieval and awareness model for industry

被引:37
|
作者
Kritzinger, E. [1 ]
Smith, E. [1 ]
机构
[1] Univ S Africa, Sch Comp, ZA-0003 Unisa, South Africa
关键词
information security; information security awareness; information security management; information security risk; information security threats; information security vulnerabilities;
D O I
10.1016/j.cose.2008.05.006
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The purpose of this paper is to present a conceptual view of an Information Security Retrieval and Awareness (ISRA) model that can be used by industry to enhance information security awareness among employees. A common body of knowledge for information security that is suited to industry and that forms the basis of this model is accordingly proposed. This common body of knowledge will ensure that the technical information security issues do not overshadow the non-technical human-related information security issues. The proposed common body of knowledge also focuses on both professionals and low-level users of information. The ISRA model proposed in this paper consists of three parts, namely the ISRA dimensions (non-technical information security issues, IT authority levels and information security documents), information security retrieval and awareness, and measuring and monitoring. The model specifically focuses on the non-technical information security that forms part of the proposed common body of knowledge because these issues have, in comparison with the technical information security issues, always been neglected. (c) 2008 Elsevier Ltd. All rights reserved.
引用
收藏
页码:224 / 231
页数:8
相关论文
共 50 条
  • [1] A situation awareness model for information security risk management
    Webb, Jeb
    Ahmad, Atif
    Maynard, Sean B.
    Shanks, Graeme
    COMPUTERS & SECURITY, 2014, 44 : 1 - 15
  • [2] A model for information security vulnerability awareness
    Mejias, Roberto J.
    Greer, Joshua J.
    Greer, Gabrila C.
    Shepherd, Morgan M.
    Reyes, Raul Y.
    Computers and Security, 2025, 151
  • [3] Study on Information Security of Industry Management
    Li Xuemei
    Li Yan
    Ding Lixing
    2009 ASIA-PACIFIC CONFERENCE ON INFORMATION PROCESSING (APCIP 2009), VOL 1, PROCEEDINGS, 2009, : 522 - +
  • [4] Information security management model
    Cribb, T
    Rao, A
    SAM'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND MANAGEMENT, VOLS 1 AND 2, 2003, : 654 - 657
  • [5] A Conceptual Analysis of Information Security Education, Information Security Training and Information Security Awareness Definitions
    Amankwa, Eric
    Loock, Marianne
    Kritzinger, Elmarie
    2014 9TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2014, : 248 - 252
  • [6] Information Security Policy Compliance: The Role of Information Security Awareness
    AL-Omari, Ahmad
    El-Gayar, Omar
    Deokar, Amit
    AMCIS 2012 PROCEEDINGS, 2012,
  • [7] Information Security Service Branding - beyond information security awareness
    Rastogi, Rahul
    von Solms, Rossouw
    IMSCI'11: THE 5TH INTERNATIONAL MULTI-CONFERENCE ON SOCIETY, CYBERNETICS AND INFORMATICS, VOL I, 2011, : 55 - 60
  • [8] Risk Management Model of Information Security in IC Manufacturing Industry
    Dai, Weihui
    Zhu, Qi
    Wang, Chunshi
    Zeng, Yujiao
    JOURNAL OF COMPUTERS, 2012, 7 (02) : 317 - 324
  • [9] Towards an Information Security Awareness Maturity Model
    Fertig, Tobias
    Schuetz, Andreas E.
    Weber, Kristin
    Mueller, Nicholas H.
    LEARNING AND COLLABORATION TECHNOLOGIES. HUMAN AND TECHNOLOGY ECOSYSTEMS, LCT 2020, PT II, 2020, 12206 : 587 - 599
  • [10] Password retrieval programs in education and their effects on information security awareness
    Antonia, Szasz
    Gabor, Kiss
    INFORMACIOS TARSADALOM, 2018, 18 (3-4): : 82 - +