Question

In: Computer Science

Describe the basic elements of human nature and how they affect information security policy development and...

Describe the basic elements of human nature and how they affect information security policy development and impact information security policy implementation issues.

Propose at least three ways that organizations can overcome these policy development and implementation issues.

Solutions

Expert Solution

Human Nature has become the weakest link in Information Security.There are multiple ways a attacker exploits the human nature.

First let us look at what are human nature or behaviour which is useful in exploiting the information security.

1.Fear:This is the common human nature which every attacker uses to steal information from the victim.

lets say an example:To get access to your Credit card /Debit Card PIN one can call you by saying we have seen a latest transaction in your credit or debit card with $10000 which directly creates fear in you and you are more tend to give the information to avoid more loses.

2 Trust: same example holds good for Trust also.

3 Emotions:This is easiest way one can easily exploit .

lets say an example:Even a Educated Person uses Password which is either a DOB of his/her child mobile number etc.

which hacker can get info easily from the social networking sites which he uses to gains access to your important account.

Now lets discuss Information Security:

Any organization or people who use computers requires a Information security in the form of three major Pillars.

1.confidentiality:means keeping sensitive information without disclosing it.

2. Integrity:means making sure the sensitive information is not tampered

3. Availability:means making sure only authorized person has access to it.

you can call this as 3 pillars of Information Security.

All these 3 Pillar get easily affected By the above Human Nature.

Confidentiality,Integrity and Availability is easily affected by Emotion.if your Confidential data has a password which is your child DOB.

Organization can Implement Information security Policy by taking below 3 major things into consideration.

1.Individual accountability

2.Auditing

3.Separation of Duty

Individual accountability:This is very important to handle the responsibility of the action.

to keep track of individual action who is authorized to that information? who is asking for that information etc.

Auditing:supports accountability therefore it is valuable to do regular auditing to check whether the system is comprised or vulnerable to get comprise etc.

Separation of Duty:it directly relates to authorization as it is an example of broader class of controls who is authorized to access the specific information and whether he is trusted for that operation etc.


Related Solutions

Describe the basic elements of human nature and how they affect information security policy development and...
Describe the basic elements of human nature and how they affect information security policy development and impact information security policy implementation issues. Propose at least three ways that organizations can overcome this policy development and implementation issues.
Define, discuss and develop information security policy with all its elements.
Define, discuss and develop information security policy with all its elements.
Identify the basic concepts of an accounting information system and describe the nature and purpose of...
Identify the basic concepts of an accounting information system and describe the nature and purpose of a subsidiary ledger.
identify the basic concepts of an accounting information system and describe the nature and purpose of...
identify the basic concepts of an accounting information system and describe the nature and purpose of a subsidiary ledger
Identify the basic concepts of an accounting information system and describe the nature and purpose of...
Identify the basic concepts of an accounting information system and describe the nature and purpose of a subsidiary ledger.
Describe the basic elements of culture.
Describe the basic elements of culture.
Establishing an effective Information Technology Security Policy Framework is critical in the development of a comprehensive...
Establishing an effective Information Technology Security Policy Framework is critical in the development of a comprehensive security program. Additionally, there are many security frameworks that organizations commonly reference when developing their security programs. Review the security frameworks provided by NIST (SP 800-53), ISO / IEC 27000 series, and COBIT. Assume that you have been hired as a consultant by a medium-sized insurance organization and have been asked to draft an IT Security Policy Framework. You may create and / or...
how does unemployment percentage of a country affect human/economic development?
how does unemployment percentage of a country affect human/economic development?
a- How does an individualist (selfish) conception of human nature affect an economic system of thought?...
a- How does an individualist (selfish) conception of human nature affect an economic system of thought? b- Compare two authors/economist’s notion of the source of “Value” and weight out whose more right.
What is your personal beliefs about the nature of human behavior, the basic tenets of human...
What is your personal beliefs about the nature of human behavior, the basic tenets of human needs, and the principles and approaches of counseling that you believe to most effectively address such behavior and needs? Include your beliefs about the therapeutic relationship, personal strengths, and characteristics that you bring to such a relationship and ethical guidelines that you consider important to adhere to within such a relationship.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT