Validation of a socio-technical management process for optimising cybersecurity practices

被引:15
|
作者
Malatji, Masike [1 ]
Marnewick, Annlize [1 ]
von Solms, Sune [2 ]
机构
[1] Univ Johannesburg, Postgrad Sch Engn Management, Gauteng, South Africa
[2] Univ Johannesburg, Dept Elect & Elect Engn Sci, Gauteng, South Africa
关键词
Cybersecurity; Information security; Optimisation; Socio-technical; Systems security; FRAMEWORK; SAFETY;
D O I
10.1016/j.cose.2020.101846
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This study developed a socio-technical management process to optimise both technical and non-technical security measures to provide optimal, rather than adequate, enterprise security safeguards. The rationale was that over the last decade, studies have consistently shown that the human being remains the weakest link in the entire enterprise security chain. As a result, the majority of cyberattacks have resulted from human behaviour or error. Despite this, evidence suggests that many enterprises are still taking overly technocentric approaches to cybersecurity risk and this has increased the chances of missing the bigger picture. Thus, a mechanism to optimise both technical and non-technical security measures by identifying and closing socio-technical security gaps in existing enterprise security frameworks was required. The mechanism was derived from the literature and validated by industry practitioners where it was found that practitioners could categorise security controls into social (human included), technical and environmental dimensions. Through this, it was found that there were mainly non-technical (social and environmental dimensions) security gaps at practitioners' organisations. To further demonstrate how this security challenge can be identified and addressed, a desktop application of the management process was carried out on the COBIT 5 for Information Security framework. The results reveal the non-technical security gaps on COBIT 5 and the management process demonstrates how these could be closed and optimised. The importance of this study is to highlight that taking overly technocentric approaches to enterprise security risk does not yield significantly positive results in protecting assets. A new approach is required and the socio-technical management process is this paper's contribution to address that security challenge. (C) 2020 Elsevier Ltd. All rights reserved.
引用
收藏
页数:17
相关论文
共 50 条
  • [1] Socio-technical systems cybersecurity framework
    Malatji, Masike
    Von Solms, Sune
    Marnewick, Annlize
    INFORMATION AND COMPUTER SECURITY, 2019, 27 (02) : 233 - 272
  • [2] Cybersecurity for SMEs: Introducing the Human Element into Socio-technical Cybersecurity Risk Assessment
    Boletsis, Costas
    Halvorsrud, Ragnhild
    Pickering, J. Brian
    Phillips, Stephen
    Surridge, Mike
    IVAPP: PROCEEDINGS OF THE 16TH INTERNATIONAL JOINT CONFERENCE ON COMPUTER VISION, IMAGING AND COMPUTER GRAPHICS THEORY AND APPLICATIONS - VOL. 3: IVAPP, 2021, : 266 - 274
  • [3] Respite for SMEs: A Systematic Review of Socio-Technical Cybersecurity Metrics
    van Haastrecht, Max
    Ozkan, Bilge Yigit
    Brinkhuis, Matthieu
    Spruit, Marco
    APPLIED SCIENCES-BASEL, 2021, 11 (15):
  • [4] Introducing Engineering as a Socio-technical Process
    Cohen, Benjamin
    Rossmann, Jenn Stroud
    Bernhardt, Kristen L. Sanford
    2014 ASEE ANNUAL CONFERENCE, 2014,
  • [5] On the socio-technical practices of the European Union territory
    Luukkonen, Juho
    Moisio, Sami
    ENVIRONMENT AND PLANNING A-ECONOMY AND SPACE, 2016, 48 (08): : 1452 - 1472
  • [6] Colour Management is a Socio-technical Problem
    O'Neill, Jacki
    Martin, David
    Colombino, Tommaso
    Roulland, Frederic
    Willamowski, Jutta
    CSCW: 2008 ACM CONFERENCE ON COMPUTER SUPPORTED COOPERATIVE WORK, CONFERENCE PROCEEDINGS, 2008, : 599 - 608
  • [7] AN INNOVATIVE SOCIO-TECHNICAL NETWORK APPROACH SUPPORTING THE BUSINESS PROCESS MANAGEMENT
    Ujwary-Gil, Anna
    Potoczek, Natalia
    PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE INNOVATION MANAGEMENT, ENTREPRENEURSHIP AND SUSTAINABILITY (IMES 2018), 2018, : 1083 - 1095
  • [8] Socio-Technical Perspective in Determining the Factors and Components for Minimizing Cybersecurity Threat
    Haryadi, Eko
    Karim, Abdul
    Salahuddin, Lizawati
    TEM JOURNAL-TECHNOLOGY EDUCATION MANAGEMENT INFORMATICS, 2023, 12 (03): : 1825 - 1837
  • [9] Socio-Technical Ecosystem Considerations: An Emergent Research Agenda for AI in Cybersecurity
    Taddeo, Mariarosaria
    Jones, Paul
    Abbas, Roba
    Vogel, Kathleen
    Michael, Katina
    IEEE Transactions on Technology and Society, 2023, 4 (02): : 112 - 118
  • [10] Impact of Socio-Technical Network on Process Performance
    Liu, Rong
    Kumar, Akhil
    2014 INTERNATIONAL CONFERENCE ON COLLABORATIVE COMPUTING: NETWORKING, APPLICATIONS AND WORKSHARING (COLLABORATECOM), 2014, : 243 - 252