Information Security and Employee Behaviour - Angus McIlwraith

Information Security and Employee Behaviour

How to Reduce Risk Through Employee Education, Training and Awareness
Buch | Hardcover
176 Seiten
2006
Gower Publishing Ltd (Verlag)
978-0-566-08647-2 (ISBN)
209,95 inkl. MwSt
zur Neuauflage
  • Titel erscheint in neuer Auflage
  • Artikel merken
Zu diesem Artikel existiert eine Nachauflage
Angus McIlwraith's book explains how corporate culture affects perceptions of risk and information security, and how this in turn affects employee behaviour. He then provides a very pragmatic solution involving strategies and techniques for educating and training employees in information security and explains how different metrics can be used to assess awareness and behaviour.
Research suggests that between 60-75% of all information security incidents are the result of a lack of knowledge and/or understanding amongst an organization's own staff. And yet the great majority of money spent protecting systems is focused on creating technical defences against external threats. Angus McIlwraith's book explains how corporate culture affects perceptions of risk and information security, and how this in turn affects employee behaviour. He then provides a pragmatic approach for educating and training employees in information security and explains how different metrics can be used to assess awareness and behaviour. Information security awareness will always be an ongoing struggle against complacency, problems associated with new systems and technology, and the challenge of other more glamorous and often short term priorities. Information Security and Employee Behaviour will help you develop the capability and culture that will enable your organization to avoid or reduce the impact of unwanted security breaches.

Angus McIlwraith has worked in the field of Information Security and Business Control for 20 years. He has for many years held (and broadcast) the view that Information Security is not making best use of time and resources by failing to address some fundamental issues. By not doing so, time and money is wasted; in some extreme circumstances, lives are being put at risk unnecessarily. Angus' professional experience was gained mainly in Financial Services. He has worked for Lloyds Bank, American Express, NatWest Bank and Standard Life, as well as working as a consultant to a wide range of international organizations. He has spoken at many conferences, including numerous Information Security Forum (ISF) Congresses, the London based COMPSEC conference, the Institute of Internal Auditors annual conference and the British Computer Society Information Security Specialist Group (BCS ISSG). Angus was an elected Member of the ruling Council of the ISF for eight years and was a member of the UK based Banking Information Security Expert Panel (BISEP). He writes regularly for many publications. He held a monthly column in Information Security Management magazine, and provided a monthly piece in Secure Computing magazine for many years.

Contents: Introduction. Part 1 A Framework for Understanding: Employee risk; Security culture; How are we perceived?; Part 1 Summary. Part 2 A Framework for Implementation: Practical strategies and techniques; Measuring awareness; Delivery media and graphic design; Conclusions; Bibliography; Index.

Erscheint lt. Verlag 28.1.2006
Sprache englisch
Maße 174 x 246 mm
Gewicht 453 g
Themenwelt Informatik Netzwerke Sicherheit / Firewall
Wirtschaft Betriebswirtschaft / Management Personalwesen
ISBN-10 0-566-08647-6 / 0566086476
ISBN-13 978-0-566-08647-2 / 9780566086472
Zustand Neuware
Haben Sie eine Frage zum Produkt?
Mehr entdecken
aus dem Bereich

von Chaos Computer Club

Buch | Softcover (2024)
KATAPULT Verlag
28,00