Factors influencing the information security behaviour of IT employees

2019 ◽  
Vol 39 (8) ◽  
pp. 862-874
Author(s):  
Val Hooper ◽  
Chris Blunt
2021 ◽  
pp. 97-107
Author(s):  
T. V. Tulupieva ◽  
M. V. Abramov ◽  
A. L. Tulupiev

The purpose of this study is to study the modernization of the model of an attacker’s social engineering attack on a user, taking into account a wider range of factors influencing the success of a social engineering attack associated with the principles of social influence. Methods. To achieve this goal, the approaches to social influence and the components of social influence were analyzed. An integrated circuit of social influence is built, grounding in the context of socio-engineering attacks. Results. A model of social influence is proposed, built in the context of an attacker’s social engineering attack on a user. A new interpretation of the term user vulnerability in the context of information security has been proposed. Conclusion. The result obtained forms the potential of filling the user and attacker models with specific vulnerabilities and competencies, which will lead to a more accurate assessment of the success of the attacker’s social engineering attack on the user, due to the aggregation of information from incidents that have occurred.


2012 ◽  
Vol 6 (3) ◽  
pp. 38-55 ◽  
Author(s):  
Zakarya A. Alzamil

Information security awareness is human and organizational attitudes which can be described as a behavior or an attitude of an organization and/or its members towards protecting the organization’s information assets. The goal of this paper is to understand the state of the information security awareness at some of the Saudi Arabians’ organizations, i.e., governments and privates by investigating the perception of their information technology’s employees. The author believes that understanding the state of information security awareness of IT employees can give a better understanding of the level of awareness at the entire organization. The results of this study show that most of the IT employees at the surveyed organizations have some misconceptions about information security practices. In addition, many responses indicated that many IT employees are not aware of the internal information security threats. Such results required very urgent actions from the top management of these organizations to consider the information security awareness programs within their public relations and training programs.


2017 ◽  
Vol 11 (5) ◽  
pp. 15-26
Author(s):  
Amjad Mahfuth ◽  
Salman Yussof ◽  
Asmidar abu bakar ◽  
Nor'ashikin Bte. Ali ◽  
Waleed Abdallah

Sign in / Sign up

Export Citation Format

Share Document