The Experts below are selected from a list of 6495 Experts worldwide ranked by ideXlab platform
Acuña, Dennis C - One of the best experts on this subject based on the ideXlab platform.
-
Manifest Observations on a Comprehensive Computer Security Policy
AIS Electronic Library (AISeL), 2018Co-Authors: Acuña, Dennis CAbstract:This paper presents the summarized results of a data gathering operation, conducted as part of IRB approved research into the effects of a comprehensive Computer Security Policy on human Computer Security Policy compliance. For this study, a comprehensive Computer Security Policy was defined as an enterprise Policy encompassing all aspects of Computer Security including IT Computer Security and OT Computer Security, as opposed to only one domain or the other. The survey instrument included a questionnaire that utilized a Likert scale for belief strength measurement. In addition to questions designed as reflective indicators for latent constructs, the questionnaire included questions to authenticate participants and to gather demographic data. The empirical findings of this study suggest manifest support, regardless of domain, for human intent to comply with a comprehensive Computer Security Policy
-
Effects of a Comprehensive Computer Security Policy on Computer Security Culture
AIS Electronic Library (AISeL), 2016Co-Authors: Acuña, Dennis CAbstract:It is well known that humans are the weakest link in Computer Security, and that developing and maintaining a culture of Computer Security is essential for managing the human aspect of Computer Security. It is less well known how a comprehensive Computer Security Policy incorporating both information technology Computer Security, and operational technology Computer Security, impacts a culture of Computer Security. While a literature review of this domain includes research on the impact of various aspects of a Computer Security Policy on Computer Security culture, no peer reviewed research was found that explained the impact of a comprehensive Computer Security Policy on Computer Security culture through an understanding of its direct or indirect effects. Thus, it is the thesis of this study that a comprehensive Computer Security Policy has a direct effect on Computer Security culture, which can be further explained through indirect effects
Muñoz Bojorge, Luis Fernando - One of the best experts on this subject based on the ideXlab platform.
-
Diseño de un SGSI que permita el control adecuado en el manejo de la información y su seguridad en una PYME de gestión de eventos y espectáculos de la ciudad de Cali.
2021Co-Authors: Muñoz Bojorge, Luis FernandoAbstract:Anexo 1 - Manual de políticas de Seguridad InformáticaEn la actualidad la información es el activo más importante en una Organización, un elemento crucial para poder ser competitivos frente a las demás empresas que hacen parte de los mercados, por lo que se deben analizar e implementar los mecanismos necesarios para protegerla. Bajo esta premisa se llevó a cabo este estudio que pretende identificar los activos informáticos en las PYMES dedicadas a la gestión de eventos y espectáculos en la ciudad de Cali y determinar los riesgos a los que se encuentran expuestos, ya que debido en muchas ocasiones se presenta desorganización en el área de Sistemas y la falta de gestión de la plataforma informática. Este análisis se realiza en varias etapas las cuales comprenden entrevistas, observación directa y la aplicación de Magerit, como metodología para analizar riesgos y poder así reconocer vulnerabilidades y amenazas. Como resultado se pretende generar un modelo del manual de políticas de seguridad informática de una empresa y el listado de los activos informáticos, así como las recomendaciones para mejorar la confidencialidad apoyándose en posibles auditorías ya realizadas anteriormente, que puedan haber generado hallazgos para ser verificados mediante esta herramienta en pro de brindar el tratamiento correspondiente.Information is currently the most important asset in an Organization, a crucial element in order to be competitive with other companies that are part of the markets, so the necessary mechanisms to protect it must be analyzed and implemented. Under this premise, this study was carried out, which aims to identify the IT assets in SMEs dedicated to the management of events and shows in the city of Cali and determine the risks to which they are exposed, since on many occasions it occurs disorganization in the Systems area and lack of management of the IT platform. This analysis is carried out in several stages which include interviews, direct observation and the application of Magerit, as a methodology to analyze risks and thus be able to recognize vulnerabilities and threats. As a result, it is intended to generate a model of a company's Computer Security Policy manual and the list of Computer assets, as well as recommendations to improve confidentiality based on possible audits already carried out previously, which may have generated findings to be verified through this tool in order to provide the corresponding treatment
Deborah A Frincke - One of the best experts on this subject based on the ideXlab platform.
-
specifying digital forensics a forensics Policy approach
Digital Forensic Research Workshop, 2007Co-Authors: Carol Taylor, Barbara Endicottpopovsky, Deborah A FrinckeAbstract:In this paper we present an approach to digital forensics specification based on forensic Policy definition. Our methodology borrows from Computer Security Policy specification, which has accumulated a significant body of research over the past 30 years. We first define the process of specifying forensics properties through a forensics Policy and then present an example application of the process. This approach lends itself to formal Policy specification and verification, which would allow for more clarity and less ambiguity in the specification process.
Suárez González Rafael - One of the best experts on this subject based on the ideXlab platform.
-
Análisis de activos de información para un sistema misional basados en la metodología Magerit v3 y la norma ISO 27001:2013.
Universidad Nacional Abierta y a Distancia UNAD, 2018Co-Authors: Suárez González RafaelAbstract:El presente documento tiene como propósito analizar los activos de información para un sistema misional, haciendo uso de la metodología MAGERIT y la norma ISO 27001:2013, con la cual se puedan aplicar la gestión de riesgos buscando de esta forma que la entidad caso de estudio pueda establecer una política de seguridad informática. Se tiene como principal finalidad analizar los activos de información de un sistema misional, el cual pude ser utilizado para la implementación del sistema de gestión de seguridad informática (SGSI) mediante un análisis actual de sus riesgos y su impacto en cada uno de los activos de una entidad. De esta forma se puede realizar la valoración de estos activos con el fin de determinar su nivel de impacto, riesgo y vulnerabilidades en los cuales se puede ver afectado, todo con el fin de llegar a sugerir controles que la entidad puede implementar basados en el anexo A de la norma ISO 27001/2013.934/5000 The purpose of this document is to analyze information assets for a mission system, using the MAGERIT methodology and the ISO 27001: 2013 standard, with which risk management can be applied, thus seeking to ensure that the case study entity can establish a Computer Security Policy. Its main purpose is to analyze the information assets of a mission system, which can be used for the implementation of the Computer Security management system (ISMS) through a current analysis of its risks and its impact on each of the assets of the company. an entity. In this way, the valuation of these assets can be carried out in order to determine their level of impact, risk and vulnerabilities in which they can be affected, all with the aim of suggesting controls that the entity can implement based on the annex. A of the ISO 27001/2013 standard
David C Littleman - One of the best experts on this subject based on the ideXlab platform.
-
integration of formal and heuristic reasoning as a basis for testing and debugging Computer Security Policy
New Security Paradigms Workshop, 1993Co-Authors: Bret J Michael, Edgar H Sibley, David C LittlemanAbstract:Errors can arise in defining and evaluating Computer Security Policy as well as in translating Computer Security Policy into procedures. The effect of such errors in Policy upon the secure operation of information systems can impose unacceptable levels of risk from the perspective of procurers and users of information systems. Relying on Computer Security paradigms based solely on formal methods makes it difficult if not impossible to detect and/or reason about certain classes of threats to Computer Security and vulnerabilities of information systems to these threats, especially for those aspects of information systems that are more readily amenable to modeling via non-formal methods. We present a paradigm integrating formal and heuristic reasoning as a basis for testing for and debugging Computer Security Policy. To illustrate our approach, and to support our arguments, we consider the problem of reasoning about the plans of an agent who may be trying to compromise the Security of an information system.