389,515 research outputs found

    Addressing The Human Factor In Information Systems Security

    Get PDF
    In this paper the historically persistent mismatch between the information systems development and security paradigms is revisited. By considering the human activity systems as a point of reference rather than a variable in information systems security, we investigate the necessity for a change in the information systems security agenda, accepting that a viable system would be more user-centric by accommodating and balancing human processes rather then entertaining an expectation of a one sided change of behaviour of the end user. This is done by drawing upon well established information systems methodologies and research

    A model to address factors that could influence the information security behaviour of computing graduates

    Get PDF
    The fact that information is ubiquitous throughout most modern organisations cannot be denied. Information is not merely used as an enabler in modern organisations today, but is also used to gain a competitive advantage over competitors. Thus, information has become one of the most important business assets. It is, therefore, imperative that organisations protect information assets as they would protect other business assets. This is typically achieved through implementing various security measures.Technological and procedural security measures are largely dependent on humans. However, the incorrect behaviour of humans poses a significant threat to the protection of these information assets. Thus, it is vital to understand how human behaviour may impact the protection of information assets. While the focus of much literature is on organisations, the focus of this research is on higher education institutions and the factors of information security, with a specific focus on influencing the information security behaviour of computing graduates. Typically, computing graduates would be employed in organisations in various careers such as software developers, network administrators, database administrators and information systems analysts. Employment in these careers means that they would be closely interacting with information assets and information systems. A real problem, as identified by this research, is that currently, many higher education institutions are not consciously doing enough to positively influence the information security behaviour of their computing graduates. This research presents a model to address various factors that could influence the information security behaviour of computing graduates. The aim of this model is to assist computing educators in influencing computing graduates to adopt more secure behaviour, such as security assurance behaviour. A literature review was conducted to identify the research problem. A number of theories such as the Theory of Planned Behaviour, Protection Motivation Theory and Social Cognitive Theory were identified as being relevant for this research as they provided a theoretical foundation for factors that could influence the information security behaviour of computing graduates. Additionally, a survey was conducted to gather the opinions and perceptions of computing educators relating to information security education in higher education institutions. Results indicated that information security is not pervasively integrated within the higher education institutions surveyed. Furthermore, results revealed that most computing students were perceived to not be behaving in a secure manner with regard to information security. This could negatively influence their information security behaviour as computing graduates employed within organisations. Computing educators therefore require assistance in influencing the information security behaviour of these computing students. The proposed model to provide this assistance was developed through argumentation and modelling

    A model to address factors that could influence the information security behaviour of computing graduates

    Get PDF
    The fact that information is ubiquitous throughout most modern organisations cannot be denied. Information is not merely used as an enabler in modern organisations today, but is also used to gain a competitive advantage over competitors. Thus, information has become one of the most important business assets. It is, therefore, imperative that organisations protect information assets as they would protect other business assets. This is typically achieved through implementing various security measures.Technological and procedural security measures are largely dependent on humans. However, the incorrect behaviour of humans poses a significant threat to the protection of these information assets. Thus, it is vital to understand how human behaviour may impact the protection of information assets. While the focus of much literature is on organisations, the focus of this research is on higher education institutions and the factors of information security, with a specific focus on influencing the information security behaviour of computing graduates. Typically, computing graduates would be employed in organisations in various careers such as software developers, network administrators, database administrators and information systems analysts. Employment in these careers means that they would be closely interacting with information assets and information systems. A real problem, as identified by this research, is that currently, many higher education institutions are not consciously doing enough to positively influence the information security behaviour of their computing graduates. This research presents a model to address various factors that could influence the information security behaviour of computing graduates. The aim of this model is to assist computing educators in influencing computing graduates to adopt more secure behaviour, such as security assurance behaviour. A literature review was conducted to identify the research problem. A number of theories such as the Theory of Planned Behaviour, Protection Motivation Theory and Social Cognitive Theory were identified as being relevant for this research as they provided a theoretical foundation for factors that could influence the information security behaviour of computing graduates. Additionally, a survey was conducted to gather the opinions and perceptions of computing educators relating to information security education in higher education institutions. Results indicated that information security is not pervasively integrated within the higher education institutions surveyed. Furthermore, results revealed that most computing students were perceived to not be behaving in a secure manner with regard to information security. This could negatively influence their information security behaviour as computing graduates employed within organisations. Computing educators therefore require assistance in influencing the information security behaviour of these computing students. The proposed model to provide this assistance was developed through argumentation and modelling

    Investigating the Relationship between Learning Styles and Delivery Methods in Information Security Awareness Programs

    Get PDF
    Information security threats are continually growing as new technologies emerge. Literature confirms that the human factor is an important issue, as cyber threats and exploitation of vulnerabilities continue to proliferate due to human error. There are significant risks associated with this, such as the organisation's reputational damage and associated costs, to name a few. Information Security Awareness (ISA) programs have proven to be one of the best methods to reduce human linked security vulnerabilities and misbehaviour, which also reduces risks. The purpose of this research is twofold. First, it is to identify and explain the value of aligning ISA programs with user-preferred learning styles and delivery methods. Second, to indicate how aligning ISA programs with preferred learning styles and delivery methods influences security posture. Using the Knowledge, Attitude, and Behaviour (KAB) model as a theoretical lens, the study depicts how information security posture can be improved through the betterment of security knowledge, attitude, and behaviour. Additionally, the aligned learning styles and delivery methods' construct was added to the KAB model to investigate the research questions. The Human Aspect of Information Systems Questionnaire (HAIS-Q) was used to measure ISA levels of organisational employees in South Africa. The chosen parts of these HAIS-Q focused on password management, email and internet use. The ISA scores are essential for this research as they indicate the current ISA levels. This result can be used to improve information security posture. The Visual, Aural, Read/Write, and Kinaesthetic (VARK) inventory model was used to better understand the provided and preferred learning styles. Additionally, ISA programs focused on text-based, video-based, and game-based delivery methods commonly used and applied in prior academic research. Using a survey methodology, the study recruited 322 South African organisational employees to complete an online questionnaire. The questionnaire contained a subset of HAIS-Q, the VARK inventory model, delivery methods, and demographic questions. Bivariate Pearson correlation tests in conjunction with the ISA scores indicated that userpreferred learning styles achieve greater ISA. The results also showed that video-based delivery methods are the most preferred but does not yield the highest ISA scores. The highest ISA scores are achieved from a mixture of delivery methods. The study proposes user aligned learning styles and preferred delivery methods to positively influence the knowledge, attitude, and behaviour leading to improved cybersecurity resilience. As a result, this leads to self-reported and risk-averse behaviour, as end-users' self-efficacy has improved

    The engineer-criminologist and "the novelty of cybercrime":a situated genealogical study of timesharing systems

    Get PDF
    The Novelty of Cybercrime is a research problem in criminology where scholars are asking whether cybercrime is a wholly new form of crime compared with traditional–terrestrial crimes and whether new criminological theories are needed to understand it. Most criminological theories focus on the human rational aspects and downplay the role of non-humans in explaining what may be novel in cybercrime. This paper shows that a sociotechnical perspective can be developed for understanding the Novelty of Cybercrime using some insights from criminology. Working from the agnosticism principle of Actor-Network Theory and a situated genealogical perspective, it is possible to see that a criminological vocabulary can accommodate both the roles and relations of rational human and non-human actors. This is achieved by proposing the concept of the engineer–criminologist, developed by conducting a study of the development of information security for timesharing systems in the 1960s and 1970s. Timesharing security engineers were facing a completely new form of rule-breaking behaviour, that of unauthorised access and at the same time they were constantly using criminological concepts to shape their design of security and explain this behaviour. The concept of engineer–criminologists affords the use of criminological concepts in the sociotechnical study of the Novelty of Cybercrime

    Towards anomaly detection for increased security in multibiometric systems: spoofing-resistant 1-median fusion eliminating outliers

    Get PDF
    Multibiometrics aims at improving biometric security in presence of spoofing attempts, but exposes a larger availability of points of attack. Standard fusion rules have been shown to be highly sensitive to spoofing attempts – even in case of a single fake instance only. This paper presents a novel spoofing-resistant fusion scheme proposing the detection and elimination of anomalous fusion input in an ensemble of evidence with liveness information. This approach aims at making multibiometric systems more resistant to presentation attacks by modeling the typical behaviour of human surveillance operators detecting anomalies as employed in many decision support systems. It is shown to improve security, while retaining the high accuracy level of standard fusion approaches on the latest Fingerprint Liveness Detection Competition (LivDet) 2013 dataset
    • …
    corecore