Internal Control of Information Sharing through user Security Behavioural Profiling

Authors

  • Suchinthi Fernando

  • Takashi Yukawa

Keywords:

information security, human behaviour, personality type, profiling, social, technological, insider threat

Abstract

This paper presents a workable solution to address the human-related information security problem of improper sharing of information by insiders with outsiders or unauthorized insiders. This system differs from most currently available information security solutions as in that, instead of relying solely on technological security measures it adapts a mixture of social and technological solutions. The presented system monitors users' security best practices and behavioural patterns and creates user security behavioural profiles and thus identifies users who might potentially pose threats to the organization's information security. The system then determines and schedules the security education and training to be given to these users.

How to Cite

Internal Control of Information Sharing through user Security Behavioural Profiling. (2014). Global Journal of Human-Social Science, 14(C1), 1-12. https://socialscienceresearch.org/index.php/GJHSS/article/view/935

References

T Asai (2007) Information security and business activities.

J Schweitzer (1996) Protecting business information.

M Bean (2008) Verizon: External breaches more common. 2008(7), 2.

B Schneier (2008) the psychology of security.

B Williams (2011) do it differently. 9(5), 6.

David Lynch (2006) Securing Against Insider Attacks. 15(5), 39-47.

A Liu (2005) a comparison of system call feature representations for insider threat detection.

R Mills (2011) A scenario-based approach to mitigating the insider threat. 9(5), 12-19.

C Vroom, R Solms (2003) Information Security: Auditing the behaviour of the employee. 401-404.

R Sabett (2011) Have you seen the latest and greatest "security game changer. 9(5), 5.

T Peltier (2002) Information security policies, procedures and standards: guidelines for effective information security management.

J Gonzalez, A Sawicka (2002) a framework for human factors in information security.

K Foley (2011) Maintaining a proactive and sustainable security programme while hosting and processing personally identifiable information. 9(5), 25-32.

S Fernando, T Yukawa (2013) Internal control of secure information and communication practices through detection of user behavioural patterns. 1248-1253.

D Lacey (2009) Managing the human factor in information security: how to win over staff and influence business.

T Young, S Varano (2006) Profiling pros and cons: an evaluation of contemporary criminal profiling methodologies.

M Thompson (2011) Functional Analysis: Behavioural Options in Relationship. 51-72.

Internal Control of Information Sharing through user Security Behavioural Profiling

Published

2014-04-19

How to Cite

Internal Control of Information Sharing through user Security Behavioural Profiling. (2014). Global Journal of Human-Social Science, 14(C1), 1-12. https://socialscienceresearch.org/index.php/GJHSS/article/view/935