Organizations' readiness for insider attacks: A process-oriented approach

被引:0
|
作者
AlGhamdi, Azzah A. [1 ,2 ,3 ,4 ]
Niazi, Mahmood [1 ,2 ]
Alshayeb, Mohammad [1 ,2 ]
Mahmood, Sajjad [1 ,2 ]
机构
[1] King Fahd Univ Petr & Minerals, Dept Informat & Comp Sci, Dhahran, Saudi Arabia
[2] King Fahd Univ Petr & Minerals, Interdisciplinary Res Ctr Intelligent Secure Syst, Dhahran, Saudi Arabia
[3] Imam Abdulrahman Bin Faisal Univ, Dept Comp Informat Syst, Al Khobar, Saudi Arabia
[4] King Fahd Univ Petr & Minerals, Dept Informat & Comp Sci, Dhahran 31261, Saudi Arabia
来源
SOFTWARE-PRACTICE & EXPERIENCE | 2024年 / 54卷 / 08期
关键词
best practices; insider attack; knowledge area; multivocal literature review; organizations; readiness model; SOFTWARE PROCESS IMPROVEMENT; USER ACCEPTANCE; MODEL; FRAMEWORK; THREATS; IMPLEMENTATION;
D O I
10.1002/spe.3327
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Context: Organizations constantly strive to protect their assets from outsider attacks by implementing various security controls, such as data encryption algorithms, intrusion detection software, firewalls, and antivirus programs. Unfortunately, attackers strike not only from outside the organization but also from within. Such internal attacks are called insider attacks or threats, and the people responsible for them are insider attackers or insider threat agents. Insider attacks pose more significant risks and can result in greater organizational losses than outsider attacks. Thus, every organization should be vigilant regarding such attackers to protect its valuable resources from harm. Finding solutions to protect organizations from such attacks is critical. Despite the importance of this topic, little research has been conducted on providing solutions to mitigate insider attacks. Objective: This study aims to develop an organizational readiness model to assess an organization's readiness for insider attacks. Method: We conducted a multivocal literature review to identify practices that can be used to assess organizations' readiness against insider attacks. These practices were grouped into different knowledge areas of insider attacks for organizations. The insider attack readiness model was developed using identified best practices and knowledge areas: compliance, top management, human resources, and technical. Results: This model was evaluated at two levels-academic and real-world environments. The evaluation results show that the proposed model can identify organizations' readiness against insider attacks. Conclusion: The proposed model can guide organizations through a secure environment against insider attacks.
引用
收藏
页码:1565 / 1589
页数:25
相关论文
共 50 条
  • [31] An Agile Approach to Improve Process-Oriented Software Development
    Herden, Adriana
    Muniz Farias, Pedro Porfirio
    Albuquerque, Adriano Bessa
    SOFTWARE ENGINEERING PERSPECTIVES AND APPLICATION IN INTELLIGENT SYSTEMS, VOL 2, 2016, 465 : 413 - 424
  • [32] A process-oriented approach to clock drawing in schizophrenia.
    Jerram, M
    Sheth, A
    Kaplan, E
    Seidman, L
    ARCHIVES OF CLINICAL NEUROPSYCHOLOGY, 1999, 14 (01) : 115 - 115
  • [33] A process-oriented approach to 'Zazie dans le metro'
    Paesani, K
    FRENCH REVIEW, 2006, 79 (04): : 762 - 778
  • [34] Process-oriented approach towards catalyst design and optimisation
    Abbasi, Mohammad Reza
    Galvanin, Federico
    Blacker, Andrew John
    Sorensen, Eva
    Shi, Yiping
    Dyer, Philip W.
    Gavriilidis, Asterios
    CATALYSIS COMMUNICATIONS, 2022, 163
  • [35] A Database to Facilitate a Process-Oriented Approach to Urban Metabolism
    Ravalde, Tom
    Keirstead, James
    JOURNAL OF INDUSTRIAL ECOLOGY, 2017, 21 (02) : 282 - 293
  • [36] A process-oriented contingency approach to responsibility in professional services
    Modell, S
    INTERNATIONAL JOURNAL OF SERVICE INDUSTRY MANAGEMENT, 1997, 8 (3-4): : 306 - +
  • [37] METACOGNITION AND PROBLEM-SOLVING - A PROCESS-ORIENTED APPROACH
    BERARDICOLETTA, B
    DOMINOWSKI, RL
    BUYER, LS
    RELLINGER, ER
    JOURNAL OF EXPERIMENTAL PSYCHOLOGY-LEARNING MEMORY AND COGNITION, 1995, 21 (01) : 205 - 223
  • [38] A PROCESS-ORIENTED APPROACH TO THE ASSESSMENT OF COGNITIVE MOTOR DISORDERS
    WESTZAAN, PS
    VANMIER, H
    MULDER, T
    HULSTIJN, W
    JOURNAL OF CLINICAL AND EXPERIMENTAL NEUROPSYCHOLOGY, 1992, 14 (03) : 390 - 390
  • [39] AN APPROACH TO DEVELOPING PROCESS-ORIENTED GROWTH AND YIELD MODELS
    AMATEIS, RL
    FOREST ECOLOGY AND MANAGEMENT, 1994, 69 (1-3) : 7 - 20
  • [40] The future of infant categorization research: A process-oriented approach
    Oakes, LM
    Madole, KL
    CHILD DEVELOPMENT, 2000, 71 (01) : 119 - 126