2010HOLISTICA – Journal of Business and Public AdministrationRequires access

Towards Information Security Awareness

Marius Gabriel Petrescu, Delia Popescu, Nicoleta Sîrbu

Open publisher page 0 citations

Abstract

Information security has come to be recognized as increasingly important because global communication and information systems allow a potentially large number of unauthorized users to access and possibly alter information from around the world. As the dependence on information systems grows, so the security of information networks becomes ever more critical to any entity, no matter if it is a company or a public institution. Information security involves both technology and people. Any security system, no matter how well designed and implemented, will have to rely on people. The fact is that users, broadly defined to include both end-users and system administrators, play a key role in implementing and correctly operating and maintaining security controls. At the same time, statistics reveal that a large number of security incidents are caused by users failing to comply with security controls. There is no use to implement complex and expensive technical solutions, if measures are not taken to deal with users security awareness rising. This paper aims to draw attention over the key role of the users in ensuring the information security and the need to develop coherent information security awareness programs, as part of the information security management process in any organization. The study is based on statistics analysis regarding information security incidents and consequent losses caused by users and the results obtained by implementing specific awareness programs.Classification-JEL: D81, L86 Keywords:security awareness, security controls, information security

About this research paper

What this paper is about

Information security has come to be recognized as increasingly important because global communication and information systems allow a potentially large number of unauthorized users to access and possibly alter information from around the world. As the dependence on information systems grows, so the security of information networks becomes ever more critical to any entity, no matter if it is a company or a public institution. Information security involves both technology and people. Any security system, no matter how well designed and implemented, will have to rely on people. The fact is that users, broadly defined to include both end-users and system administrators, play a key role in implementing and correctly operating and maintaining security controls. At the same time, statistics reveal that a large number of security incidents are caused by users failing to comply with security controls. There is no use to implement complex and expensive technical solutions, if measures are not taken to deal with users security awareness rising. This paper aims to draw attention over the key role of the users in ensuring the information security and the need to develop coherent information security awareness programs, as part of the information security management process in any organization. The study is based on statistics analysis regarding information security incidents and consequent losses caused by users and the results obtained by implementing specific awareness programs.Classification-JEL: D81, L86 Keywords:security awareness, security controls, information security

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Information security has come to be recognized as increasingly important because global communication and information systems allow a potentially large number of unauthorized users to access and possibly alter information from around the world. As the dependence on information systems grows, so the security of information networks becomes ever more critical to any entity, no matter if it is a company or a public institution. Information security involves both technology and people. Any security system, no matter how well designed and implemented, will have to rely on people. The fact is that users, broadly defined to include both end-users and system administrators, play a key role in implementing and correctly operating and maintaining security controls. At the same time, statistics reveal that a large number of security incidents are caused by users failing to comply with security controls. There is no use to implement complex and expensive technical solutions, if measures are not taken to deal with users security awareness rising. This paper aims to draw attention over the key role of the users in ensuring the information security and the need to develop coherent information security awareness programs, as part of the information security management process in any organization. The study is based on statistics analysis regarding information security incidents and consequent losses caused by users and the results obtained by implementing specific awareness programs.Classification-JEL: D81, L86 Keywords:security awareness, security controls, information security

Key concepts: Information security management, Security information and event management, Information security, Computer security, Security service, Information security standards, Certified Information Security Manager, Information security audit

Related papers

Back to paper searchBrowse research topicsOriginal source
Towards Information Security Awareness — Research Paper | ScholarLens