Information security management: An information security retrieval and awareness model for industry

被引:37
|
作者
Kritzinger, E. [1 ]
Smith, E. [1 ]
机构
[1] Univ S Africa, Sch Comp, ZA-0003 Unisa, South Africa
关键词
information security; information security awareness; information security management; information security risk; information security threats; information security vulnerabilities;
D O I
10.1016/j.cose.2008.05.006
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The purpose of this paper is to present a conceptual view of an Information Security Retrieval and Awareness (ISRA) model that can be used by industry to enhance information security awareness among employees. A common body of knowledge for information security that is suited to industry and that forms the basis of this model is accordingly proposed. This common body of knowledge will ensure that the technical information security issues do not overshadow the non-technical human-related information security issues. The proposed common body of knowledge also focuses on both professionals and low-level users of information. The ISRA model proposed in this paper consists of three parts, namely the ISRA dimensions (non-technical information security issues, IT authority levels and information security documents), information security retrieval and awareness, and measuring and monitoring. The model specifically focuses on the non-technical information security that forms part of the proposed common body of knowledge because these issues have, in comparison with the technical information security issues, always been neglected. (c) 2008 Elsevier Ltd. All rights reserved.
引用
收藏
页码:224 / 231
页数:8
相关论文
共 50 条
  • [31] Information Security Awareness of School Administrators
    Karabatak, SongUl
    Karabatak, Murat
    2019 7TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSICS AND SECURITY (ISDFS), 2019,
  • [32] Analyzing trajectories of information security awareness
    Tsohou, Aggeliki
    Karyda, Maria
    Kokolakis, Spyros
    Kiountouzis, Evangelos
    INFORMATION TECHNOLOGY & PEOPLE, 2012, 25 (03) : 327 - 352
  • [33] A Research on Students' Information Security Awareness
    Tekerek, Mehmet
    Tekerek, Adem
    TURKISH JOURNAL OF EDUCATION, 2013, 2 (03): : 61 - 70
  • [34] A dynamic manpower forecasting model for the information security industry
    Park, Sang-Hyun
    Lee, Sang M.
    Yoon, Seong No
    Yeon, Seung-Jun
    INDUSTRIAL MANAGEMENT & DATA SYSTEMS, 2008, 108 (3-4) : 368 - 384
  • [35] Security Awareness: The First Step in Information Security Compliance Behavior
    Hwang, Inho
    Wakefield, Robin
    Kim, Sanghyun
    Kim, Taeha
    JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2021, 61 (04) : 345 - 356
  • [36] Is information security under control? Investigating quality in information security management
    Baker, Wade H.
    Wallace, Linda
    IEEE SECURITY & PRIVACY, 2007, 5 (01) : 36 - 44
  • [37] Comparison of Information Security Systems for Asymptotic Information Security Management Critical Information Infrastructures
    Erokhin, Sergey
    Petukhov, Andrey
    Pilyugin, Pavel
    PROCEEDINGS OF THE 28TH CONFERENCE OF OPEN INNOVATIONS ASSOCIATION FRUCT, 2021, : 89 - 95
  • [38] A Network Security Situational Awareness Model Based on Information Fusion
    Abasi
    ADVANCES IN MECHATRONICS, AUTOMATION AND APPLIED INFORMATION TECHNOLOGIES, PTS 1 AND 2, 2014, 846-847 : 1632 - 1635
  • [39] Enhancing Information Security Education and Awareness: proposed characteristics for a Model
    Amankwa, Eric
    Loock, Marianne
    Kritzinger, Elmarie
    2015 SECOND INTERNATIONAL CONFERENCE ON INFORMATION SECURITY AND CYBER FORENSICS (INFOSEC), 2015, : 72 - 77
  • [40] IGNORANCE TO AWARENESS: TOWARDS AN INFORMATION SECURITY AWARENESS PROCESS
    Gundu, T.
    Flowerday, S. V.
    SAIEE AFRICA RESEARCH JOURNAL, 2013, 104 (02): : 69 - 79