Social Engineering for Diagnostic the Information Security Culture

被引:0
|
作者
Marchand-Nino, William-Rogelio [1 ]
Guzman Fonseca, Bruno Paolo [1 ]
机构
[1] Univ Nacl Agr Selva, Grp Invest Redes Seguridad & Gest TI, Tingo Maria, Peru
关键词
social engineering; information security culture; security; cybersecurity; phishing;
D O I
暂无
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
In the process of diagnosing the culture of information security in an organization, it is considered two methods, the first one is the application of an ISCA (Information Security Culture Assessment) survey questionnaire and the second one based on social engineering techniques such as phishing, answering the question, How can a diagnosis be made effectively of the level of information security culture within an organization? with the objective of determining which of the two methods is the most effective and realistic for the diagnosis of the information security culture. This helps to understand and have a real and complete perception of the behavior and reaction of the users against the attacks of threat actors who make use of persuasion and manipulation tactics in order to obtain confidential or sensitive information. A description of these two methods is applied to a case study (public university). As a result, it is obtained that it is not enough to perform a diagnosis based on questionnaires because they can be relatively subjective in the sense of the way in which users respond to questions or statements. Evidence of controlled social engineering attacks that demonstrate in more detail the real behavior of users should be considered. Based on this more complete knowledge, appropriate strategies can be formulated for the change or strengthening of the security culture that ultimately contributes to the purpose of protecting information assets.
引用
收藏
页码:233 / 238
页数:6
相关论文
共 50 条
  • [1] Social engineering in the context of ensuring information security
    Mamedova, Natalia
    Urintsov, Arkadiy
    Staroverova, Olga
    Ivanov, Evgeniy
    Galahov, Dmitriy
    [J]. INTERNATIONAL SCIENTIFIC AND PRACTICAL CONFERENCE CURRENT ISSUES OF LINGUISTICS AND DIDACTICS: THE INTERDISCIPLINARY APPROACH IN HUMANITIES AND SOCIAL SCIENCES (CILDIAH-2019), 2019, 69
  • [2] SOCIAL ENGINEERING: AN INFORMATION SECURITY THREAT IN ENTERPRISES
    Acilar, Ali
    Bastug, Ayse
    [J]. GLOBAL BUSINESS RESEARCH CONGRESS (GBRC) 2016, VOL 2, 2016, 2 : 289 - 297
  • [3] An Overview of Social Engineering in the Context of Information Security
    Kaushalya, S. A. D. T. P.
    Randeniya, R. M. R. S. B.
    Liyanage, A. D. S.
    [J]. 2018 5TH IEEE INTERNATIONAL CONFERENCE ON ENGINEERING TECHNOLOGIES AND APPLIED SCIENCES (IEEE ICETAS), 2018,
  • [4] Social engineering: Application of psychology to information security
    Del Pozo, Ivan
    Iturralde, Mauricio
    Restrepo, Felipe
    [J]. 2018 IEEE 6TH INTERNATIONAL CONFERENCE ON FUTURE INTERNET OF THINGS AND CLOUD WORKSHOPS (W-FICLOUD 2018), 2018, : 108 - 114
  • [5] Shaping intention to resist social engineering through transformational leadership, information security culture and awareness
    Flores, Waldo Rocha
    Ekstedt, Mathias
    [J]. COMPUTERS & SECURITY, 2016, 59 : 26 - 44
  • [6] Helping the hacker? Library information, security, and social engineering
    Thompson, Samuel T. C.
    [J]. INFORMATION TECHNOLOGY AND LIBRARIES, 2006, 25 (04) : 222 - 225
  • [7] Enacting social engineering: the emotional experience of information security deception
    Alexandra Pimentel
    Kevin F. Steinmetz
    [J]. Crime, Law and Social Change, 2022, 77 : 341 - 361
  • [8] Social Engineering: The Neglected Human Factor for Information Security Management
    Luo, Xin
    Brody, Richard
    Seazzu, Alessandro
    Burd, Stephen
    [J]. INFORMATION RESOURCES MANAGEMENT JOURNAL, 2011, 24 (03) : 1 - 8
  • [9] Enacting social engineering: the emotional experience of information security deception
    Pimentel, Alexandra
    Steinmetz, Kevin F.
    [J]. CRIME LAW AND SOCIAL CHANGE, 2022, 77 (03) : 341 - 361
  • [10] Performing social engineering: A qualitative study of information security deceptions
    Steinmetz, Kevin F.
    Pimentel, Alexandra
    Goe, W. Richard
    [J]. COMPUTERS IN HUMAN BEHAVIOR, 2021, 124