Value-focused assessment of ICT security awareness in an academic environment

نویسندگان

  • Lynette Drevin
  • Hennie A. Kruger
  • Tjaart Steyn
چکیده

Security awareness is important to reduce human error, theft, fraud, and misuse of computer assets. A strong ICT security culture cannot develop and grow in a company without awareness programmes. This paper focuses on ICT security awareness and how to identify key areas of concern to address in ICT security awareness programmes by making use of the value-focused approach. The result of this approach is a network of objectives where the fundamental objectives are the key areas of concern that can be used in decision making in security planning. The fundamental objectives were found to be in line with the acknowledged goals of ICT security, e.g. confidentiality, integrity and availability. Other objectives that emerged were more on the social and management side, e.g. responsibility for actions and effective use of resources. a 2006 Elsevier Ltd. All rights reserved.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Value-Focused Assessment of Information Communication and Technology Security Awareness in an Academic Environment

The aim of this paper is to introduce the approach of value-focused thinking when identifying information and communications technology (ICT) security awareness aspects. Security awareness is important to reduce human error, theft, fraud, and misuse of computer assets. A strong ICT security culture cannot develop and grow in a company without awareness programmes. How can personnel follow the r...

متن کامل

A Framework for Evaluating ICT Security Awareness

ICT resources are important assets of any organization and the protection of these resources are equally important. To be able to protect themselves and their profitability, many organizations have established information security awareness programs. In order for a security awareness program to add value to an organization and at the same time make a contribution to the field of information sec...

متن کامل

Identity Theft - Empirical evidence from a Phishing Exercise

Identity theft is an emerging threat in our networked world and more individuals and companies fall victim to this type of fraud. User training is an important part of ICT security awareness; however, IT management must know and identify where to direct and focus these awareness training efforts. A phishing exercise was conducted in an academic environment as part of an ongoing information secu...

متن کامل

An Information Security Training and Awareness Approach (ISTAAP) to Instil an Information Security-Positive Culture

This paper proposes a unique information security training and awareness approach (ISTAAP) that can be used to instil an information security-positive culture which will assist in addressing the risk that human behaviour poses to the protection of information. An information security culture assessment tool is used as the critical diagnostic instrument to assess the information security culture...

متن کامل

The Effect of Portfolio Assessment on the Development of Metacognitive Awareness in EFL Learners' Translating in the Academic Context

A translation portfolio is a systematic collection of student's translations or reports of tasks torepresent a variety of student's achievements in the translation course over a specified period oftime. This paper aims to investigate the effect of portfolio assessment in the translatingclassroom in an attempt to examine its impact on EFL learners' metacognitive awareness. Todetermine the impact...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • Computers & Security

دوره 26  شماره 

صفحات  -

تاریخ انتشار 2007