Human Aspects of Information Assurance: A Questionnaire-based Quantitative Approach to Assessment

نویسندگان

  • Evangelos D. Frangopoulos
  • Mariki M. Eloff
  • Lucas M. Venter
چکیده

In work previously done by the authors, various human aspects of Information Assurance were identified. These comprise Social and Psychological aspects, the effects of Psycho-social risk at the workplace, the application of Influence techniques, user response to Social Engineering Methods and choices based on Economic considerations. Even though these aspects have been shown to gravely affect Information Assurance, the current level of their incorporation in the Plan-Do-Check-Act virtuous cycle of Information Security Management Systems, leaves a lot to be desired. In order to combine the findings of previous research and effectively provide quantified input that is usable in the context of an Information Security Management System (ISMS), an appropriate methodology must be introduced. This paper sets the framework and constraints for the methodology and by examining the merits and shortcomings of existing work in the field, proposes a questionnaire-based quantitative methodology that meets the set requirements. This will ultimately provide a tool for rapid, consistent and repeatable assessment of the Information Assurance level, as this is affected by the identified human aspects of Information Assurance.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Qualitative and quantitative approaches to analyse reliability of a mechatronic system: a case

The main research intent of this paper is to introduce the use of fault tree analysis (FTA) and failure mode and effects analysis (FMEA) in conjunction to analyse the risk and reliability of a complex mechatronic system in both qualitative and quantitative manner. The major focus is on handling imprecise and vague information with the help of fuzzy synthesis of information. A complex mechatroni...

متن کامل

Risk Analysis of Operating Room Using the Fuzzy Bayesian Network Model

To enhance Patient’s safety, we need effective methods for risk management. This work aims to propose an integrated approach to risk management for a hospital system. To improve patient’s safety, we should develop flexible methods where different aspects of risk and type of information are taken into consideration. This paper proposes a fuzzy Bayesian network to model and analyze risk in the op...

متن کامل

A Pathology of the Human Resources Management System in the Ministry of Education and Ways to Improve the System (A Quantitative Study)

 The present research has endeavored to identify the flaws in the human resource management system in Iran's educational administration and resent suggestions for improvement. Quantitative in nature, this study has taken a descriptive approach regarding its objective while the approach toward data collection has been of the survey kind. Teachers and principals of state-owned schools in the prov...

متن کامل

Measuring user's emotional experience in two tools using an integrated method based on task analysis

Background and Objectives: Human factors are critical in the research and development of various products, but the wideness and unclarity of different aspects of these factors make it difficult to extract the demands of users. Studying emotional aspects of users' behavior with respect to products, as well as interviewing them, is considered an efficient tool for extracting design demands. Me...

متن کامل

Educational needs assessment model of Abadan Oil Refining Company with the approach of realizing the strategies of the organization

The purpose of‌ study is to present the educational needs assessment model of Abadan Oil Refining Company with the approach of realizing the organization's strategies‌‌. The research is of applied type and in terms of combined method‌‌. The study population includes experts of Abadan Oil Refining Company‌‌. Using purposive sampling, the Delphi panel consisting of 15 people was formed‌‌. Then, b...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2014