• DocumentCode
    228931
  • Title

    Towards metamodel-based approach for Information Security Awareness Management

  • Author

    Jama, Ahmed Yousuf ; Siraj, Maheyzah Md ; Kadir, Rashidah

  • Author_Institution
    Inf. Assurance & Security Res. Group, Univ. Teknol. Malaysia, Skudai, Malaysia
  • fYear
    2014
  • fDate
    26-27 Aug. 2014
  • Firstpage
    316
  • Lastpage
    321
  • Abstract
    Information technology and information system have been used widely in many fields such as in business, education, marketing, transportation and medical. Security aspect plays a vital role and thus turns into a challenging issue. The security should be readily installed and resistance to various numbers of potential attacks likes Spyware, Phishing / Spam and Malwares (Virus, Worm and Trojans). It is important to have specific countermeasures that could minimize the harm to enterprises. Thus, increasing the awareness to optimal level is the main target of enterprise management. Unfortunately, the main reason that fails many existing enterprise´ Information Security Awareness Management (ISAM) models is the complexity and inflexibility. Complexity means the model´s structure is less practical (for instance, the implementation needs to be deployed manually). Inflexibility means it cannot support multiple kinds of businesses and did not consider security aspects. In this paper, we surveyed and discussed several existing ISAM models considering the security issues in current enterprise. We proposed a metamodel-based approach for ISAM that can offer efficiency and security that brings out clearly significant benefits by highlighting the organization overall level of awareness whether it is strong enough or weak. This will help many users in this domain to easily understand the important concepts required for their own information security awareness management.
  • Keywords
    business data processing; information systems; invasive software; ISAM models; business; education; enterprise information security awareness management; information system; information technology; malwares; marketing; medical; metamodel-based approach; phishing; potential attacks; spam; spyware; transportation; trojans; virus; worm; Analytical models; Biological system modeling; Computers; Information security; Organizations; enterprise system; information security awareness; malware; management evaluation; threat;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Biometrics and Security Technologies (ISBAST), 2014 International Symposium on
  • Conference_Location
    Kuala Lumpur
  • Print_ISBN
    978-1-4799-6443-7
  • Type

    conf

  • DOI
    10.1109/ISBAST.2014.7013141
  • Filename
    7013141