减少网络攻击数据丢失的数据保护改进策略

Strategies for Improving Data Protection to Reduce Data Loss from Cyberattacks

Management Science · 2019
被引 0
人大 A+FT50UTD24ABS 4*

中文导读

通过对佛罗里达州一家中型企业的案例调查,探索了信息系统和信息技术领导者成功的数据保护策略,识别出人员、流程和技术三大主题,旨在帮助减少数据丢失和财务影响。

Abstract

Accidental and targeted data breaches threaten sustainable business practices and personal privacy, exposing all types of businesses to increased data loss and financial impacts. This single case study was conducted in a medium-sized enterprise located in Brevard County, Florida, to explore the successful data protection strategies employed by the information system and information technology business leaders. Actor-network theory was the conceptual framework for the study with a graphical syntax to model data protection strategies. Data were collected from semistructured interviews of 3 business leaders, archival documents, and field notes. Data were analyzed using thematic, analytic, and software analysis, and methodological triangulation. Three themes materialized from the data analyses: people--inferring security personnel, network engineers, system engineers, and qualified personnel to know how to monitor data; processes--inferring the activities required to protect data from data loss; and technology--inferring scientific knowledge used by people to protect data from data loss. The findings are indicative of successful application of data protection strategies and may be modeled to assess vulnerabilities from technical and nontechnical threats impacting risk and loss of sensitive data. The implications of this study for positive social change include the potential to alter attitudes toward data protection, creating a better environment for people to live and work; reduce recovery costs resulting from Internet crimes, improving social well-being; and enhance methods for the protection of sensitive, proprietary, and personally identifiable information, which advances the privacy rights for society.

数据保护策略网络攻击数据丢失行动者网络理论