Controls Mitigating the Risk of Confidential Information Disclosure by Facebook: Essential Concern in Auditing Information Security

被引:0
|
作者
Kuyumdzhiev, Ivan Ognyanov [1 ]
机构
[1] Ivan Ognyanov Kuyumdzhiev, Varna, Bulgaria
关键词
Facebook; audit; information security; security policy;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Facebook allows people to easily share information about themselves which in some cases could be classified as confidential or sensitive in the organisation they're working for. In this paper we discuss the type of data stored by Facebook and the scope of the terms "confidential" and "sensitive data". The intersection of these areas shows that there is high possibility for confidential data disclosure in organisations with none or ineffective security policy. This paper proposes a strategy for managing the risks of information leakage. We define five levels of controls against posting non-public data on Facebook-security policy, applications installed on employees' workstations, specific router software or firmware, software in the cloud, Facebook itself. Advantages and disadvantages of every level are evaluated. As a result we propose developing of new control integrated in the social media.
引用
收藏
页码:113 / 119
页数:7
相关论文
共 50 条
  • [1] Auditing Security of Information Flows
    Kozlovs, Dmitrijs
    Kirikova, Marite
    PERSPECTIVES IN BUSINESS INFORMATICS RESEARCH, BIR 2016, 2016, 261 : 204 - 219
  • [2] Mitigating Privacy Issues on Facebook by Implementing Information Security Awareness with Islamic Perspectives
    Faisal, Ammy Amelia
    Nisa, Bsek Salihatun
    Ibrahim, Jamaludin
    2013 5TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY FOR THE MUSLIM WORLD (ICT4M), 2013,
  • [3] LAWYER AND CLIENT - LIABILITY FOR DISCLOSURE OF CONFIDENTIAL INFORMATION
    HAMMOND, RG
    CANADIAN BAR REVIEW-REVUE DU BARREAU CANADIEN, 1984, 62 (03): : 408 - 418
  • [4] Information Disclosure and the Diffusion of Information Security Attacks
    Mitra, Sabyasachi
    Ransbotham, Sam
    INFORMATION SYSTEMS RESEARCH, 2015, 26 (03) : 565 - 584
  • [5] Information Disclosure as a Means to Security
    Rabinovich, Zinovi
    Jiang, Albert Xin
    Jain, Manish
    Xu, Haifeng
    PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON AUTONOMOUS AGENTS & MULTIAGENT SYSTEMS (AAMAS'15), 2015, : 645 - 653
  • [6] FACEBOOK - PRIVACY SETTINGS AND PERSONAL INFORMATION DISCLOSURE
    Pavlicek, Antonin
    IDIMT-2016- INFORMATION TECHNOLOGY, SOCIETY AND ECONOMY STRATEGIC CROSS-INFLUENCES, 2016, 45 : 133 - 144
  • [7] Compelled Disclosure of Confidential Information in Patient Safety Research
    Du, Li
    Murdoch, Blake
    Chiu, Carina
    Caulfield, Timothy
    JOURNAL OF PATIENT SAFETY, 2021, 17 (03) : 200 - 206
  • [8] NEWSMENS PRIVILEGE AGAINST DISCLOSURE OF CONFIDENTIAL SOURCES AND INFORMATION
    NELSON, HL
    VANDERBILT LAW REVIEW, 1971, 24 (04) : 667 - 681
  • [10] Information security: Auditing the behaviour of the employee
    Vroom, C
    von Solms, R
    SECURITY AND PRIVACY IN THE AGE OF UNCERTAINTY, 2003, 122 : 401 - 404