信息安全人因风险研究进展综述

被引:6
作者
曾忠平
机构
[1] 不详
[2] 华中科技大学公共管理学院
[3] 不详
关键词
信息安全; 人因风险; 风险评估; 风险管理;
D O I
暂无
中图分类号
G203 [信息资源及其管理];
学科分类号
1204 ; 1402 ;
摘要
对信息安全人因风险研究国内外理论与应用现状进行了归纳总结和分析,对人因风险研究进展做出了综合评价。针对现有信息安全风险成因过于复杂、研究对象过于片面、人因风险测度尚不完善以及缺乏对人因风险全面整合的能力等缺陷,认为未来研究方向应该加强人因风险因素识别、数据采集和建模研究,从过程视角、人因风险评估等途径实现对人因风险的动态控制管理,并将人因风险和用户行为进行整合以激励用户自觉产生积极的信息安全行为,促进企业和组织构建更安全的信息环境。
引用
收藏
页码:6 / 11+22 +22
页数:7
相关论文
共 22 条
  • [1] 信息安全综述
    沈昌祥
    张焕国
    冯登国
    曹珍富
    黄继武
    [J]. 中国科学(E辑:信息科学) , 2007, (02) : 129 - 150
  • [2] From culture to disobedience: Recognising the varying user acceptance of IT security[J] . Steven Furnell,Kerry-Lynn Thomson.Computer Fraud & Security . 2009 (2)
  • [3] Assessment of information impacts in power system security against malicious attacks in a general framework
    Bompard, E.
    Napoli, R.
    Xue, F.
    [J]. RELIABILITY ENGINEERING & SYSTEM SAFETY, 2009, 94 (06) : 1087 - 1094
  • [4] Self-efficacy in information security: Its influence on end users' information security practice behavior[J] . Hyeun-Suk Rhee,Cheongtag Kim,Young U. Ryu.Computers & Security . 2009 (8)
  • [5] Human and organizational factors in computer and information security: Pathways to vulnerabilities[J] . Sara Kraemer,Pascale Carayon,John Clem.Computers & Security . 2009 (7)
  • [6] Information security policy: An organizational-level process model[J] . Kenneth J. Knapp,R. Franklin Morris,Thomas E. Marshall,Terry Anthony Byrd.Computers & Security . 2009 (7)
  • [7] Improving information security awareness and behaviour through dialogue, participation and collective reflection. An intervention study[J] . Eirik Albrechtsen,Jan Hovden.Computers & Security . 2009 (4)
  • [8] An integrated view of human, organizational, and technological challenges of IT security management[J] . Rodrigo Werlinger,Kirstie Hawkey,Konstantin Beznosov.Information Management & Computer Security . 2009 (1)
  • [9] A test of interventions for security threats from social engineering[J] . Michael Workman.Information Management & Computer Security . 2008 (5)
  • [10] How significant is human error as a cause of privacy breaches? An empirical study and a framework for error management[J] . Divakaran Liginlal,Inkook Sim,Lara Khansa.Computers & Security . 2008 (3)