People and Human Factors
摘要
Managing cybersecurity solely through technology is always challenging, as dealing with cyberattacks requires a socio-technical strategy. This chapter focuses on this area in the context of governance in human-technology interaction. From a cybersecurity governance perspective, we investigate how firms use people to manage cyber risk effectively. People can assist in identifying and mitigating risks before they have a significant negative impact because they are frequently the first line of defense against cyber threats. The ways that people can support cyber risk management are discussed and include security awareness, training and education, corporate culture, policy compliance, reporting suspicious activity, adhering to established incident response protocols, and aiding in the identification of the issue’s origin and breadth, and assisting in the identification of potential risks and vulnerabilities inside an organization.