Controls Mitigating the Risk of Confidential Information Disclosure by Facebook: Essential Concern in Auditing Information Security

被引:0
|
作者
Kuyumdzhiev, Ivan Ognyanov [1 ]
机构
[1] Ivan Ognyanov Kuyumdzhiev, Varna, Bulgaria
关键词
Facebook; audit; information security; security policy;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Facebook allows people to easily share information about themselves which in some cases could be classified as confidential or sensitive in the organisation they're working for. In this paper we discuss the type of data stored by Facebook and the scope of the terms "confidential" and "sensitive data". The intersection of these areas shows that there is high possibility for confidential data disclosure in organisations with none or ineffective security policy. This paper proposes a strategy for managing the risks of information leakage. We define five levels of controls against posting non-public data on Facebook-security policy, applications installed on employees' workstations, specific router software or firmware, software in the cloud, Facebook itself. Advantages and disadvantages of every level are evaluated. As a result we propose developing of new control integrated in the social media.
引用
收藏
页码:113 / 119
页数:7
相关论文
共 50 条