An information security awareness capability model (ISACM)
Paper
Paper/Presentation Title | An information security awareness capability model (ISACM) |
---|---|
Presentation Type | Paper |
Authors | Poepjes, Robert (Author) and Lane, Michael (Author) |
Editors | Williams, Trish, Johnstone, Mike and Valli, Craig |
Journal or Proceedings Title | Proceedings of the 10th Australian Information Security Management Conference (SECAU 2012) |
ERA Conference ID | 42535 |
Number of Pages | 8 |
Year | 2012 |
Place of Publication | Perth, Western Australia |
ISBN | 9780729807029 |
Web Address (URL) of Paper | http://www.researchgate.net/publication/233960123_AN_INFORMATION_SECURITY_AWARENESS_CAPABILITY_MODEL_(ISACM) |
Conference/Event | 10th Australian Information Security Management Conference (SECAU 2012) |
Australian Information Security Management Conference | |
Event Details | Australian Information Security Management Conference Rank B B B B B B B |
Event Details | 10th Australian Information Security Management Conference (SECAU 2012) Event Date 03 to end of 05 Dec 2012 Event Location Perth, Western Australia |
Abstract | A lack of information security awareness within some parts of society as well as some organisations continues to exist today. Whilst we have emerged from the threats of late 1990s of virus such as Code Red and Melissa, through to the phishing emails of the mid 2000’s and the financial damage some such as the Nigerian scam caused, we continue to react poorly to new threats such as demanding money via SMS with a promise of death to those that won’t pay. So is this lack of awareness translating into problems within the workforce? There is often a lack of knowledge as to what is an appropriate level of awareness for information security controls across an organisation. This paper presents the development of a theoretical framework and model that combines aspects of information security best practice standards as presented in ISO/IEC 27002 with theories of Situation Awareness. The resultant model is an information security awareness capability model (ISACM). A preliminary survey is being used to develop the Awareness Importance element of the model and will leverage the opinions of information security professionals. A subsequent survey is also being developed to measure the Awareness Capability element of the model. This will present a number of scenarios with a series of cascading questions that test Level 1 situation awareness (perception), Level 2 situation awareness (comprehension) and finally Level 3 situation awareness (projection). |
Keywords | IT security, awareness, situation awareness, ISO27000, awareness importance, awareness capability, awareness risk |
ANZSRC Field of Research 2020 | 469999. Other information and computing sciences not elsewhere classified |
460499. Cybersecurity and privacy not elsewhere classified | |
460908. Information systems organisation and management | |
Public Notes | No evidence of copyright restrictions preventing deposit. |
Byline Affiliations | School of Information Systems |
Institution of Origin | University of Southern Queensland |
https://research.usq.edu.au/item/q197y/an-information-security-awareness-capability-model-isacm
Download files
2379
total views492
total downloads6
views this month2
downloads this month