错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Human-Centric Management of Information Security

  • Linda Rosenkron,
  • Mari Seeba,
  • Mohamad Gharib,
  • Kuldar Taveter

摘要

Cybersecurity is no longer seen as merely a technical issue—organisations are complex sociotechnical systems involving various stakeholders and cybersecurity issues concern every person related to the system. Non-technical stakeholders typically experience difficulties understanding the technical part of the cybersecurity frameworks they must apply, especially identifying business processes and their information resources that are subject to various cybersecurity threats. This study fills the gap and presents a Process and Resources elicitation Method (PReM) that enables non-technical organisation members to identify relevant processes and information for applying the cybersecurity framework enforced in Estonia: the Estonian Information Security Standard (E-ITS). PReM uses a goal-oriented approach and enables the identification of business processes and information resources needed by these processes. PReM was evaluated in a case study within the RIHAMU (abbreviation of “Risk Management model” in Estonian) project, where the organisations under the Estonian Ministry of Social Affairs were tasked to apply E-ITS. The results are promising – organisations managed well with goal and role modelling and were able to identify relevant business processes and information required for applying the E-ITS cybersecurity framework.