Information security management: An information security retrieval and awareness model for industry

被引:37
|
作者
Kritzinger, E. [1 ]
Smith, E. [1 ]
机构
[1] Univ S Africa, Sch Comp, ZA-0003 Unisa, South Africa
关键词
information security; information security awareness; information security management; information security risk; information security threats; information security vulnerabilities;
D O I
10.1016/j.cose.2008.05.006
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The purpose of this paper is to present a conceptual view of an Information Security Retrieval and Awareness (ISRA) model that can be used by industry to enhance information security awareness among employees. A common body of knowledge for information security that is suited to industry and that forms the basis of this model is accordingly proposed. This common body of knowledge will ensure that the technical information security issues do not overshadow the non-technical human-related information security issues. The proposed common body of knowledge also focuses on both professionals and low-level users of information. The ISRA model proposed in this paper consists of three parts, namely the ISRA dimensions (non-technical information security issues, IT authority levels and information security documents), information security retrieval and awareness, and measuring and monitoring. The model specifically focuses on the non-technical information security that forms part of the proposed common body of knowledge because these issues have, in comparison with the technical information security issues, always been neglected. (c) 2008 Elsevier Ltd. All rights reserved.
引用
收藏
页码:224 / 231
页数:8
相关论文
共 50 条
  • [41] Application of Cloud Security Terminal in Information Management of Power Industry
    Jiang, Jiang
    Xie, Hanyang
    Li, Yuqing
    Luo, Jinman
    ADVANCED HYBRID INFORMATION PROCESSING, ADHIP 2022, PT I, 2023, 468 : 771 - 783
  • [42] Analysing of the Information Security Awareness of the Economic Information Technology Students
    Kiss, Gabor
    Szasz, Antonia
    2016 17TH IEEE INTERNATIONAL SYMPOSIUM ON COMPUTATIONAL INTELLIGENCE AND INFORMATICS (CINTI 2016), 2016, : 213 - 218
  • [43] Determining the effects of information security knowledge on information security awareness via structural equation modelings
    Saracli, Sinan
    Erdogmus, Atilgan
    HACETTEPE JOURNAL OF MATHEMATICS AND STATISTICS, 2019, 48 (04): : 1201 - 1212
  • [44] The impact of information richness on information security awareness training effectiveness
    Shaw, R. S.
    Chen, Charlie C.
    Harris, Albert L.
    Huang, Hui-Jou
    COMPUTERS & EDUCATION, 2009, 52 (01) : 92 - 100
  • [45] The security model to combine the corporate and information security
    Virtanen, T
    TRUSTED INFORMATION: THE NEW DECADE CHALLENGE, 2001, 65 : 305 - 316
  • [46] A novel approach for improving information security management and awareness for home environments
    Alotaibi, Fayez Ghazai
    Clarke, Nathan
    Furnell, Steven M.
    INFORMATION AND COMPUTER SECURITY, 2021, 29 (01) : 25 - 48
  • [47] Towards Metamodel-based Approach for Information Security Awareness Management
    Jama, Ahmed Yousuf
    Siraj, Maheyzah Md
    Kadir, Rashidah
    2014 INTERNATIONAL SYMPOSIUM ON BIOMETRICS AND SECURITY TECHNOLOGIES (ISBAST), 2014, : 316 - 321
  • [48] Health care management and information systems security: awareness, training or education?
    Katsikas, SK
    INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 2000, 60 (02) : 129 - 135
  • [49] An enhanced smartphone security model based on information security management system (ISMS)
    Jong Hyuk Park
    Ki Jung Yi
    Young-Sik Jeong
    Electronic Commerce Research, 2014, 14 : 321 - 348
  • [50] An enhanced smartphone security model based on information security management system (ISMS)
    Park, Jong Hyuk
    Yi, Ki Jung
    Jeong, Young-Sik
    ELECTRONIC COMMERCE RESEARCH, 2014, 14 (03) : 321 - 348