Organizations' readiness for insider attacks: A process-oriented approach

被引:0
|
作者
AlGhamdi, Azzah A. [1 ,2 ,3 ,4 ]
Niazi, Mahmood [1 ,2 ]
Alshayeb, Mohammad [1 ,2 ]
Mahmood, Sajjad [1 ,2 ]
机构
[1] King Fahd Univ Petr & Minerals, Dept Informat & Comp Sci, Dhahran, Saudi Arabia
[2] King Fahd Univ Petr & Minerals, Interdisciplinary Res Ctr Intelligent Secure Syst, Dhahran, Saudi Arabia
[3] Imam Abdulrahman Bin Faisal Univ, Dept Comp Informat Syst, Al Khobar, Saudi Arabia
[4] King Fahd Univ Petr & Minerals, Dept Informat & Comp Sci, Dhahran 31261, Saudi Arabia
来源
SOFTWARE-PRACTICE & EXPERIENCE | 2024年 / 54卷 / 08期
关键词
best practices; insider attack; knowledge area; multivocal literature review; organizations; readiness model; SOFTWARE PROCESS IMPROVEMENT; USER ACCEPTANCE; MODEL; FRAMEWORK; THREATS; IMPLEMENTATION;
D O I
10.1002/spe.3327
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Context: Organizations constantly strive to protect their assets from outsider attacks by implementing various security controls, such as data encryption algorithms, intrusion detection software, firewalls, and antivirus programs. Unfortunately, attackers strike not only from outside the organization but also from within. Such internal attacks are called insider attacks or threats, and the people responsible for them are insider attackers or insider threat agents. Insider attacks pose more significant risks and can result in greater organizational losses than outsider attacks. Thus, every organization should be vigilant regarding such attackers to protect its valuable resources from harm. Finding solutions to protect organizations from such attacks is critical. Despite the importance of this topic, little research has been conducted on providing solutions to mitigate insider attacks. Objective: This study aims to develop an organizational readiness model to assess an organization's readiness for insider attacks. Method: We conducted a multivocal literature review to identify practices that can be used to assess organizations' readiness against insider attacks. These practices were grouped into different knowledge areas of insider attacks for organizations. The insider attack readiness model was developed using identified best practices and knowledge areas: compliance, top management, human resources, and technical. Results: This model was evaluated at two levels-academic and real-world environments. The evaluation results show that the proposed model can identify organizations' readiness against insider attacks. Conclusion: The proposed model can guide organizations through a secure environment against insider attacks.
引用
收藏
页码:1565 / 1589
页数:25
相关论文
共 50 条
  • [1] Process-Oriented Learning Requirements for Employees and for Organizations
    Pircher, Richard
    Zenk, Lukas
    Risku, Hanna
    PROCEEDINGS OF WORLD ACADEMY OF SCIENCE, ENGINEERING AND TECHNOLOGY, VOL 14, 2006, 14 : 408 - 412
  • [2] Management Strategy for Adapting to Process-Oriented Organizations
    Ahmetagic, Esad
    Tumbas, Pere
    Piukovic, Blazenka
    STRATEGIC MANAGEMENT, 2012, 17 (03): : 47 - 53
  • [3] Automated information systems generation for process-oriented organizations
    Duarte, Francisco J.
    Machado, Ricardo J.
    Fernandes, Joao M.
    QUATIC 2007: 6TH INTERNATIONAL CONFERENCE ON THE QUALITY OF INFORMATION AND COMMUNICATIONS TECHNOLOGY, PROCEEDINGS, 2007, : 223 - +
  • [4] A reference framework for process-oriented software development organizations
    Fernandes J.M.
    Duarte F.J.
    Software & Systems Modeling, 2005, 4 (1) : 94 - 105
  • [5] A PROCESS-ORIENTED APPROACH TO THE CONTRACT CLAUSE
    不详
    YALE LAW JOURNAL, 1980, 89 (08): : 1623 - 1651
  • [6] Process-Oriented Approach to Fixture Design
    Ivanov, Vitalii
    ADVANCES IN DESIGN, SIMULATION AND MANUFACTURING, 2019, : 42 - 50
  • [7] Tugger Train A process-oriented Approach
    Baerwolff, Christian
    16. FLURFORDERZEUGTAGUNG 2011, 2011, 2136 : 159 - 168
  • [8] A process-oriented approach to mantle geochemistry
    Stracke, Andreas
    CHEMICAL GEOLOGY, 2021, 579 (579)
  • [9] Reusing operational requirements: A process-oriented approach
    Darimont, R
    Souquieres, J
    RE '97 - PROCEEDINGS OF THE THIRD IEEE INTERNATIONAL SYMPOSIUM ON REQUIREMENTS ENGINEERING, 1997, : 16 - 25
  • [10] Bangladeshi Migration to Singapore: A Process-Oriented Approach
    Mathews, Mathew
    JOURNAL OF CONTEMPORARY ASIA, 2018, 48 (05) : 856 - 859