An information security retrieval and awareness model for industry
Elroy Eugene Smith, Elmarie Kritzinger
Abstract
Elroy Eugene Smith, Elmarie Kritzinger
Abstract
The present study originated from a realisation that employees in an organisation should be aware of their role and responsibility towards securing the information they work with. Further motivation for the study was the realisation that information is the lifeline of many organisations and should therefore be properly secured to ensure that it is not compromised in any way. The ultimate responsibility for the management of Information Security lies with top management. A further incentive for this study was the realisation that many Information Security breaches occur due to human action. Information Security should therefore also address the non-technical, human-related Information Security issues and not focus on the technical issues only. This study is principally aimed at making a contribution towards enhancing Information Security awareness in industry, and for this reason, culminates in an Information Security Retrieval and Awareness (ISRA) model specifically developed for the industry sector. An investigation into the current status of Information Security awareness in each of the sectors of the Information Security community (i.e. government, industry and academia) indicated that there is an urgent need for enhancing Information Security awareness in each of these sectors. The researcher proceeded to explore the ongoing development of Information Security over the past few years. These developments created paradigm shifts ranging from a purely technical approach towards Information Security, towards a more managerial way of protecting information, and currently focusing on creating an Information Security culture within organisations. With the development of Information Security came Information Security documents that address the management of Information Security. Ten of these documents were identified as the basis for a Common Body of Knowledge for Information Security suited to industry. After having explored the limitations of current efforts to create such a Common Body of Knowledge, a Common Body of Knowledge for Information Security suited to industry that addresses these limitations was proposed. The proposed Common Body of Knowledge addresses the Information Security responsibility of both users with little or no formal background on Information Security, and of specialists in the field. In addition, the proposed Common Body of Knowledge explicitly distinguishes between the technical and the non-technical, human-related Information Security issues. A model was accordingly proposed that enhances Information Security awareness in the said domain in the sense that it is based on a Common Body of Knowledge for Information Security suited to industry. In addition, the ISRA model ensures that stakeholders are made aware of the Information Security issues relevant to their specific job category only, to prevent them from being burdened with irrelevant information. Finally, the ISRA model allows stakeholders to retrieve specific information related to Information Security at any time.
OpenAlex reports 13 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
The present study originated from a realisation that employees in an organisation should be aware of their role and responsibility towards securing the information they work with. Further motivation for the study was the realisation that information is the lifeline of many organisations and should therefore be properly secured to ensure that it is not compromised in any way. The ultimate responsibility for the management of Information Security lies with top management. A further incentive for this study was the realisation that many Information Security breaches occur due to human action. Information Security should therefore also address the non-technical, human-related Information Security issues and not focus on the technical issues only. This study is principally aimed at making a contribution towards enhancing Information Security awareness in industry, and for this reason, culminates in an Information Security Retrieval and Awareness (ISRA) model specifically developed for the industry sector. An investigation into the current status of Information Security awareness in each of the sectors of the Information Security community (i.e. government, industry and academia) indicated that there is an urgent need for enhancing Information Security awareness in each of these sectors. The researcher proceeded to explore the ongoing development of Information Security over the past few years. These developments created paradigm shifts ranging from a purely technical approach towards Information Security, towards a more managerial way of protecting information, and currently focusing on creating an Information Security culture within organisations. With the development of Information Security came Information Security documents that address the management of Information Security. Ten of these documents were identified as the basis for a Common Body of Knowledge for Information Security suited to industry. After having explored the limitations of current efforts to create such a Common Body of Knowledge, a Common Body of Knowledge for Information Security suited to industry that addresses these limitations was proposed. The proposed Common Body of Knowledge addresses the Information Security responsibility of both users with little or no formal background on Information Security, and of specialists in the field. In addition, the proposed Common Body of Knowledge explicitly distinguishes between the technical and the non-technical, human-related Information Security issues. A model was accordingly proposed that enhances Information Security awareness in the said domain in the sense that it is based on a Common Body of Knowledge for Information Security suited to industry. In addition, the ISRA model ensures that stakeholders are made aware of the Information Security issues relevant to their specific job category only, to prevent them from being burdened with irrelevant information. Finally, the ISRA model allows stakeholders to retrieve specific information related to Information Security at any time.
Key concepts: Information security management, Information security, Security information and event management, Information security standards, Certified Information Security Manager, Information security audit, Realisation, Business