An Information Security Awareness Program to Address Common Security Concerns in IT Unit

被引:11
作者
Al Awawdeh, Shadi [1 ]
Tubaishat, Abdallah [1 ]
机构
[1] Zayed Univ, Coll Technol Innovat, Abu Dhabi, U Arab Emirates
来源
2014 11TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: NEW GENERATIONS (ITNG) | 2014年
关键词
security; awareness; human factor; training; IT unit;
D O I
10.1109/ITNG.2014.67
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Educated and trained people are critical success factor in any IT work environment to minimize threats or misuse of the organizational assets that may damage the growth, excellence, and efficiency of any business. However, humans are always the weakest point in any security plan. Awareness is by far the most successful technique that does not cost much when compared with training and education and may reduce the total expenditure on security. Having a properly planned information security awareness program greatly impact the raising of the awareness level among the organization's staff. Information Technology unit represents a critical success factor in knowledge management and plays a major role in the decision-making process within any organization. We assess that the initial step in delivering any security awareness plan to the business should start from within IT unit, and this is aligned with the perception that security is the sole responsibility of the IT department. Most of the former studies proposed general information security awareness programs and guidelines, but few of them targeted IT unit. The purpose of this research is to propose an information security awareness program (ISAP) to be used by IT unit to enhance the level of information security standard regardless of the organization type. Our research study differs from other studies in that we targeted the IT unit when building ISAP. Furthermore, we identify several awareness knowledge areas for each subdivision.
引用
收藏
页码:273 / 278
页数:6
相关论文
共 32 条
[1]  
Al-awadi M., SUCCESS FACTORS INFO
[2]  
Aloul Fadi A., 2012, Journal of Advances in Information Technology, V3, P176, DOI 10.4304/jait.3.3.176-183
[3]  
[Anonymous], 2013, WALL STREET J
[4]  
[Anonymous], EMPLOYEES BEHAV IS S
[5]  
[Anonymous], 2011, Cybercrime: Protecting Against the Growing Threat - Global Economic Crime Survey
[6]  
[Anonymous], 2003, NIST80050
[7]  
[Anonymous], 1998, NIST80016
[8]  
Ashraf S., 2005, Organization need and everyone's responsibility: Information security awareness
[9]  
Australian National Audit Office, 2005, 23200506 AUSTR NAT A
[10]  
Breznik L., 2012, Economic and Business Review, V14, P251