Skip to main content
QUICK REVIEW

[论文解读] The need for effective information security awareness practices in Oman higher educational institutions

Rajasekar Ramalingam, Shimaz Khan|arXiv (Cornell University)|Feb 21, 2016
Information and Cyber Security参考文献 3被引用 7
一句话总结

本研究通过调查,探讨了阿曼高等教育机构中的信息安全意识水平,揭示了用户意识和培训方面存在显著差距。研究提出了一套量身定制的安全意识模型,以提升机构的网络安全部实践,旨在减少人为相关漏洞,并增强阿曼教育部门的组织韧性。

ABSTRACT

The revolution of internet technology and its usage have led a significant increase in the number of online transactions and electronic data transfer, parallely increased the number of cybercrime incidents around the world. Steady economic growth in the Sultanate of Oman accelerated the volume of online utilization for e-commerce, banking, communication, education and so forth. Normally attackers target the users who ignore security practices due to the lack of information security awareness. Unawareness of information security practices, user negligence, lack of awareness programs and trainings are the root cause for information security threats. Earlier studies reveal there is a considerable and continuous cybercrime incident in Oman which compromises the security policy of the organizations, affecting the business continuity and the economic growth. In this study, a survey was performed among the educational institutions in Oman to investigate the level of information security awareness and based on the study, a security awareness model is proposed to enable information security practices in the educational institutions.

研究动机与目标

  • 评估阿曼高等教育机构中教职工和学生当前的信息安全意识状况。
  • 识别导致安全意识低下、包括缺乏培训和机构政策在内的关键因素。
  • 应对由于用户疏忽和不良安全实践导致的阿曼教育领域网络犯罪威胁日益增长的问题。
  • 开发一种符合语境的、支持学术机构可持续信息安全实践的安全意识模型。

提出的方法

  • 在阿曼多个高等教育机构开展调查,收集有关安全意识水平的数据。
  • 分析调查结果,识别用户行为模式、知识差距以及机构在安全培训方面的不足。
  • 基于识别出的缺陷和网络安全教育的最佳实践,设计一个全面的安全意识模型。
  • 将机构、行为和技术要素整合进一个整体模型,以适用于学术环境实施。
  • 使该模型与阿曼的国家网络安全部目标及教育领域需求保持一致。
  • 通过教育和信息技术领域利益相关者的反馈,验证了该模型的相关性。

实验结果

研究问题

  • RQ1阿曼高等教育机构中用户的信息安全意识当前处于何种水平?
  • RQ2这些机构中安全意识低下及网络威胁易感性增加的主要原因是什么?
  • RQ3机构政策和培训项目在多大程度上影响用户的信息安全行为?
  • RQ4在阿曼大学中,一个有效且符合语境的安全意识模型必须包含哪些核心要素?
  • RQ5所提出的模型如何提升阿曼高等教育部门的网络安全部韧性?

主要发现

  • 阿曼高等教育机构中相当大比例的用户缺乏基本的信息安全意识,使其更容易受到网络威胁。
  • 缺乏结构化的安全意识项目和定期培训被确认为不良安全实践的主要促成因素。
  • 用户疏忽和缺乏机构政策被持续关联到教育机构中网络犯罪事件的增加。
  • 调查结果显示,仅有少数机构设有正式且持续的安全意识倡议。
  • 所提出的安全部意识模型与机构需求及国家网络安全部目标高度契合。
  • 研究证实,有针对性的、机构特定的安全意识项目可显著降低学术环境中的人为安全风险。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。