Validation of a socio-technical management process for optimising cybersecurity practices

被引:15
|
作者
Malatji, Masike [1 ]
Marnewick, Annlize [1 ]
von Solms, Sune [2 ]
机构
[1] Univ Johannesburg, Postgrad Sch Engn Management, Gauteng, South Africa
[2] Univ Johannesburg, Dept Elect & Elect Engn Sci, Gauteng, South Africa
关键词
Cybersecurity; Information security; Optimisation; Socio-technical; Systems security; FRAMEWORK; SAFETY;
D O I
10.1016/j.cose.2020.101846
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This study developed a socio-technical management process to optimise both technical and non-technical security measures to provide optimal, rather than adequate, enterprise security safeguards. The rationale was that over the last decade, studies have consistently shown that the human being remains the weakest link in the entire enterprise security chain. As a result, the majority of cyberattacks have resulted from human behaviour or error. Despite this, evidence suggests that many enterprises are still taking overly technocentric approaches to cybersecurity risk and this has increased the chances of missing the bigger picture. Thus, a mechanism to optimise both technical and non-technical security measures by identifying and closing socio-technical security gaps in existing enterprise security frameworks was required. The mechanism was derived from the literature and validated by industry practitioners where it was found that practitioners could categorise security controls into social (human included), technical and environmental dimensions. Through this, it was found that there were mainly non-technical (social and environmental dimensions) security gaps at practitioners' organisations. To further demonstrate how this security challenge can be identified and addressed, a desktop application of the management process was carried out on the COBIT 5 for Information Security framework. The results reveal the non-technical security gaps on COBIT 5 and the management process demonstrates how these could be closed and optimised. The importance of this study is to highlight that taking overly technocentric approaches to enterprise security risk does not yield significantly positive results in protecting assets. A new approach is required and the socio-technical management process is this paper's contribution to address that security challenge. (C) 2020 Elsevier Ltd. All rights reserved.
引用
收藏
页数:17
相关论文
共 50 条
  • [21] Process science: the interdisciplinary study of socio-technical change
    Jan vom Brocke
    Wil M. P. van der Aalst
    Nicholas Berente
    Boudewijn van Dongen
    Thomas Grisold
    Waldemar Kremser
    Jan Mendling
    Brian T. Pentland
    Maximilian Roeglinger
    Michael Rosemann
    Barbara Weber
    Process Science, 1 (1):
  • [22] Sustainability transitions and final consumption: practices and socio-technical systems
    McMeekin, Andrew
    Southerton, Dale
    TECHNOLOGY ANALYSIS & STRATEGIC MANAGEMENT, 2012, 24 (04) : 345 - 361
  • [23] A socio-technical approach to improving the systems development process
    Patnayakuni, Ravi
    Ruppel, Cynthia P.
    INFORMATION SYSTEMS FRONTIERS, 2010, 12 (02) : 219 - 234
  • [24] SOCIO-TECHNICAL CONCERNS
    CAMPBELL, RM
    MECHANICAL ENGINEERING, 1978, 100 (12) : 36 - 36
  • [25] Socio-technical evolution
    Rosenlyst, Martin
    Siboni, Henrik
    Rasmussen, Steen
    2018 CONFERENCE ON ARTIFICIAL LIFE (ALIFE 2018), 2018, : 99 - 100
  • [26] Socio-technical challenges towards data-driven and integrated urban water management: A socio-technical network approach
    Manny, Liliane
    SUSTAINABLE CITIES AND SOCIETY, 2023, 90
  • [27] Review of knowledge management systems as socio-technical system
    Assegaff, Setiawan
    Hussin, Ab Razak Che
    International Journal of Computer Science Issues, 2012, 9 (5 5-3): : 129 - 134
  • [28] Socio-technical transformations of Indore's waste management
    Tiwari, Ankit
    Sharma, Pritee
    INTERNATIONAL JOURNAL OF ENVIRONMENT AND WASTE MANAGEMENT, 2024, 33 (01) : 43 - 58
  • [29] Complex socio-technical systems: Characterization and management guidelines
    Righi, Angela Weber
    Saurin, Tarcisio Abreu
    APPLIED ERGONOMICS, 2015, 50 : 19 - 30
  • [30] Knowledge Management in the Construction Industry: A Socio-Technical Perspective
    Pichura, Alexander
    CONSTRUCTION MANAGEMENT AND ECONOMICS, 2006, 24 (10) : 1101 - 1102