Internal Control of Information Sharing through user Security Behavioural Profiling
Keywords:
information security, human behaviour, personality type, profiling, social, technological, insider threat
Abstract
This paper presents a workable solution to address the human-related information security problem of improper sharing of information by insiders with outsiders or unauthorized insiders. This system differs from most currently available information security solutions as in that, instead of relying solely on technological security measures it adapts a mixture of social and technological solutions. The presented system monitors users' security best practices and behavioural patterns and creates user security behavioural profiles and thus identifies users who might potentially pose threats to the organization's information security. The system then determines and schedules the security education and training to be given to these users.
Downloads
- Article PDF
- TEI XML Kaleidoscope (download in zip)* (Beta by AI)
- Lens* NISO JATS XML (Beta by AI)
- HTML Kaleidoscope* (Beta by AI)
- DBK XML Kaleidoscope (download in zip)* (Beta by AI)
- LaTeX pdf Kaleidoscope* (Beta by AI)
- EPUB Kaleidoscope* (Beta by AI)
- MD Kaleidoscope* (Beta by AI)
- FO Kaleidoscope* (Beta by AI)
- BIB Kaleidoscope* (Beta by AI)
- LaTeX Kaleidoscope* (Beta by AI)
How to Cite
References
T Asai (2007) Information security and business activities.
J Schweitzer (1996) Protecting business information.
M Bean (2008) Verizon: External breaches more common. 2008(7), 2.
B Schneier (2008) the psychology of security.
B Williams (2011) do it differently. 9(5), 6.
David Lynch (2006) Securing Against Insider Attacks. 15(5), 39-47.
A Liu (2005) a comparison of system call feature representations for insider threat detection.
R Mills (2011) A scenario-based approach to mitigating the insider threat. 9(5), 12-19.
C Vroom, R Solms (2003) Information Security: Auditing the behaviour of the employee. 401-404.
R Sabett (2011) Have you seen the latest and greatest "security game changer. 9(5), 5.
T Peltier (2002) Information security policies, procedures and standards: guidelines for effective information security management.
J Gonzalez, A Sawicka (2002) a framework for human factors in information security.
K Foley (2011) Maintaining a proactive and sustainable security programme while hosting and processing personally identifiable information. 9(5), 25-32.
S Fernando, T Yukawa (2013) Internal control of secure information and communication practices through detection of user behavioural patterns. 1248-1253.
D Lacey (2009) Managing the human factor in information security: how to win over staff and influence business.
T Young, S Varano (2006) Profiling pros and cons: an evaluation of contemporary criminal profiling methodologies.
M Thompson (2011) Functional Analysis: Behavioural Options in Relationship. 51-72.
Published
2014-04-19
Issue
Section
License
Copyright (c) 2014 Authors and Global Journals Private Limited

This work is licensed under a Creative Commons Attribution 4.0 International License.