Information security management: An information security retrieval and awareness model for industry

被引:37
|
作者
Kritzinger, E. [1 ]
Smith, E. [1 ]
机构
[1] Univ S Africa, Sch Comp, ZA-0003 Unisa, South Africa
关键词
information security; information security awareness; information security management; information security risk; information security threats; information security vulnerabilities;
D O I
10.1016/j.cose.2008.05.006
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The purpose of this paper is to present a conceptual view of an Information Security Retrieval and Awareness (ISRA) model that can be used by industry to enhance information security awareness among employees. A common body of knowledge for information security that is suited to industry and that forms the basis of this model is accordingly proposed. This common body of knowledge will ensure that the technical information security issues do not overshadow the non-technical human-related information security issues. The proposed common body of knowledge also focuses on both professionals and low-level users of information. The ISRA model proposed in this paper consists of three parts, namely the ISRA dimensions (non-technical information security issues, IT authority levels and information security documents), information security retrieval and awareness, and measuring and monitoring. The model specifically focuses on the non-technical information security that forms part of the proposed common body of knowledge because these issues have, in comparison with the technical information security issues, always been neglected. (c) 2008 Elsevier Ltd. All rights reserved.
引用
收藏
页码:224 / 231
页数:8
相关论文
共 50 条
  • [21] Individual differences and Information Security Awareness
    McCormac, Agata
    Zwaans, Tara
    Parsons, Kathryn
    Calic, Dragana
    Butavicius, Marcus
    Pattinson, Malcolm
    COMPUTERS IN HUMAN BEHAVIOR, 2017, 69 : 151 - 156
  • [22] Model of enterprise's information security management
    Omelchenko, Tatiana
    Umnitsyn, Mikhail
    Nikishova, Arina
    Sadovnikova, Natalia
    PROCEEDINGS OF THE IV INTERNATIONAL RESEARCH CONFERENCE INFORMATION TECHNOLOGIES IN SCIENCE, MANAGEMENT, SOCIAL SPHERE AND MEDICINE (ITSMSSM 2017), 2017, 72 : 182 - 187
  • [23] Impact of information security awareness on information security compliance of academic library staff in Turkiye
    Kavak, Ali
    JOURNAL OF ACADEMIC LIBRARIANSHIP, 2024, 50 (05):
  • [24] Information security management model for integration platforms
    Wilk, Jaroslaw
    2015 FORTH INTERNATIONAL CONFERENCE ON E-TECHNOLOGIES AND NETWORKS FOR DEVELOPMENT, 2015, : 22 - 27
  • [25] The Use of an Information Security Vocabulary Test to Assess Information Security Awareness - An Exploratory Study
    Kruger, H. A.
    Drevin, L.
    Steyn, T.
    PROCEEDINGS OF THE SOUTH AFRICAN INFORMATION SECURITY MULTI-CONFERENCE, 2010, : 13 - 22
  • [26] Gamification of Information Security Awareness and Training
    Gjertsen, Eyvind Garder B.
    Gjaere, Erlend Andreas
    Bartnes, Maria
    Flores, Waldo Rocha
    ICISSP: PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2017, : 59 - 70
  • [27] A prototype for assessing information security awareness
    Kruger, H. A.
    Kearney, W. D.
    COMPUTERS & SECURITY, 2006, 25 (04) : 289 - 296
  • [28] Mediating effects of information security awareness
    van der Schyff, Karl
    Flowerday, Stephen
    COMPUTERS & SECURITY, 2021, 106
  • [29] Building an information security awareness program
    Marshall, P
    JOURNAL OF GOVERNMENT INFORMATION, 2002, 29 (06): : 431 - 433
  • [30] Information Security Awareness of School Administrators
    Karabatak, SongUl
    Karabatak, Murat
    2019 7TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSICS AND SECURITY (ISDFS), 2019,