保障人的安全:组织环境中员工安全漏洞风险研究

Securing the human: Employee security vulnerability risk in organizational settings

Journal of the Association for Information Science and Technology (JASIST) · 2017
被引 29
ABS 3

中文导读

研究员工的人口统计、公司特定和技能特征如何预测其成为安全漏洞受害者的可能性,基于对250名美国IT咨询公司员工的调查,分析钓鱼、密码、自带设备和公司配发笔记本电脑四类风险。

Abstract

As organizational security breaches increase, so too does the need to fully understand the human factors that lead to these breaches and take the necessary steps to minimize threats. The present study evaluates how three sets of employee characteristics (demographic, company‐specific, and skills‐based) predict an employee's likelihood of becoming a security breach victim. In order to move beyond traditional evaluations of security threats, which generally consider security threats individually, analyses in this paper approach security vulnerability from a more holistic approach to analyze four risk categories concurrently: phishing, passwords, bring your own device (BYOD), and company‐supplied laptops. Findings from a survey of 250 employees at a medium‐sized American information technology (IT) consulting firm identify higher‐risk employees across the four risk areas and provide new insights into the challenges organizations face when trying to ensure the protection of company data.

信息安全员工行为组织管理网络安全