Information security: Risks related to the cultural capital of personnel (Review)

Allerton Press - Tập 42 - Trang 41-52 - 2015
L. V. Astakhova1
1South Ural State University, Chelyabinsk, Russia

Tóm tắt

Based on the analysis of such current trends in the field of information security and the post-industrial economy as the paradigm of “security through development,” the culture of information security as a necessity to reduce information-security risks, and the approach that considers a person as capital, the concept of the cultural capital of corporate information security as an integral part of the cultural capital of an organization is justified. A procedure is developed for the risk assessement of personnel in information security, based on the index of confidence as the ratio of the individual cultural information-security capital to the corporate cultural information-security capital.

Tài liệu tham khảo

Study of leaks of confidential information in the first half of 2014. http://www.infowatch.ru/report2014_half. Aleksentsev, A.I., The nature and relations between the concepts of “protection of information”, “security of information”, and “information security”, Bezop. Inf. Tekhnol., 1999, no. 1, pp. 44–47. Prozorov, A., The human factor in information security standards. http://www.slideshare.net/AndreyProzorov/ss-27026263. GOST (State Standard) R ISO/MEK 27001:2006 Information Technology. Methods and Means of Ensuring of Security. Management Systems of Information Security. Requirements, 2008. ISO/IEC 27002:2005, BS 7799-1:2005,BS ISO/IEC 17799:2005. Information technology. Security techniques. Code of practice for information security management, 2005. GOST (State Standard) R ISO/MEK 31010-2011. Risk management. Risk assessment methods, 2012. Standart TsB RF STO BR IBBS-1.0-2014. Obespechenie informatsionnoi bezopasnosti organizatsii bankovskoi sistemy RF. Obshchie polozheniya (Standard TsB RF STO BR IBBS-1.0-2014. Ensuring of Information Security of Russian Federation Bank System Organization. The General Positions), Moscow, 2014. Standart TsB RF STO BR IBBS-1.2-2014. Obespechenie informatsionnoi bezopasnosti organizatsii bankovskoi sistemy RF. Metodika otsenki sootvetstviya informatsionnoi bezopasnosti organizatsii bankovskoi sistemy Rossiiskoi Federatsii trebovaniyam STO BR IBBS-1.0-2014 (Standard TsB RF STO BR IBBS-1.0-2014. Ensuring of Information Security of Russian Federation Bank System Organization. Methodology of Estimation of Information Security of Russian Federation Bank System Organization Correspondence to STO BR IBBS-1.0-2014 Requirements), Moscow, 2014. RS BR IBBS-2.2-2009. Obespechenie informatsionnoi bezopasnosti organizatsii bankovskoi sistemy Rossiiskoi Federatsii. Metodika otsenki riskov narusheniya informatsionnoi bezopasnosti (Ensuring of Information Security of Russian Federation Bank System Organizations. Methodology of Estimation of Risks of Violation of Information Security), Moscow, 2009. Tulup’eva, T.V., Tulup’ev, A.L., and Azarov, A.A., Psychological aspects of information safety assessment in the context of socio-engineering attacks, Med.-Biol. Sots.-Psikhol. Probl. Bezop. v Chrezvych. Sit., 2013, no. 1, pp. 77–83. Azarov, A.A., Tulup’ev, A.L., Solovtsov, N.B., and Tulup’eva, T.V., Acceleration of information system users’ security assessment calculations due to elimination of unlikely trajectories of socio-engineering attacks, Tr. SPIIRAN, 2013, no. 2(25), pp. 171–181. Zaitsev, A.S. and Malyuk, A.A., Study of the insider problem, Vestn. Ross. Gos. Gum. Univ., 2012, no. 14(94), pp. 114–134. Rytov, M.Yu. and Leksikov, E.V., Formalization of the process of evaluation of staff’s loyalty to reduce information security risks, Inform. Besop., 2014, vol. 17, no. 2, pp. 276–279. Lukatskii, A.V., How to evaluate the awareness enhancing program? http://lukatsky.blogspot.ru/2011/08/blog-post_19.html. Astakhova, L.V., Problem of identification and assessment of human resources vulnerability in the information security of the organization, Vestn. Yuzhn. Ural. Gos. Univ. Ser. Komp’yut. Tekhnol., Upravl. Radioelektron., 2013, vol. 13, no. 1, pp. 79–83. Dolgov, K.M., Human capital and culture, Vestn. MGIMO-univ., 2013, no. 3(30), pp. 135–136. Kuz’minov, Ya., Bendukidze, K., and Yudkevich, M., How the science of markets becomes a science about society, Vopr. Ekon., 2005, no. 12, p. 73. Kos’mina, E.A., Metelev, S.E., and Kos’min, A.D., Kul’turnyi kapital obshchestva v real’nom materiale funktsioniruyushchei organizatsii (Cultural Capital of the Society in a Real Material of a Functioning Organization), Moscow: Ekonomika, 2007. Tikhomirova, O.G., Organizatsionnaya kul’tura: formirovanie, razvitie i otsenka (Organizational Culture: Formation, Development, and Evaluation), SPB: Izd-Vo ITMO, 2008. Bourdieu, P., Forms of the capital. http://gtmar-ket.ru/laboratory/expertize/2009/2601. Bol’shakov, N.V., Measurement of the cultural capital: from theory to practice, Monit. Obshchestv. Mneniya: Ekon. Sots. Peremeny, 2013, no. 6(118), pp. 3–12. Gorbunova, S.V., Accumulation of the human capital in real economy workers, Cand. Sci. (Econ.) Dissertation, Yekaterinburg: In-t Ekon. UrO RAN, 2009. Radaev, V.V., The concept of the capital, forms of the capital and their conversion, Ekon. Sots., 2002, vol. 3, no. 4. Samarina, I.S., Cultural capital of students in the conditions of Russia’s transition to the innovative type of development: Cand. Sci. (Soc.) Dissertation, Saratov: Sarat. Gos. Sots.-Ekonom. Un-t, 2010. Trosbi, D., Cultural capital, J. Cult. Econ., 1999, no. 12. Furs, V., Social theory in a changing world: Towards a dynamic concept of social? in Sochineniya, 2 vols., Vilnus: EGU, 2012, vol. 1, pp. 412–432. Soboleva, I., Paradoxes of measuring the human capital, Vopr. Ekon., 2009, no. 9, pp. 51–70. Tolstobrov, G.M., Formation and evaluation of the intellectual capital in the information economy, Cand. Sci. (Econ.) Dissertation, Sankt-Peterburg, 2010. Markaryan, K.V., Human capital in the post-industrial economy, Extended Abstract of Doctoral (Econ.) Dissertation, Moscow, 2005. Kastryulina, Yu.M., Analysis of methods for assessing the human capital of economic entities, Nauchn. Zh. NIU ITMO. Ser. Ekon. Ekol. Menedzhm., 2013, no. 1, p. 19. Pliskevich, N.M., Chelovecheskii kapital v transformiruyushcheisya Rossii (Human Capital in Transforming Russia), Moscow: Institut Ekonomiki RAN, 2012. Shash, N.N., Development of human capital in organization: Theory and methodology, Doctoral (Econ.) Dissertation, Saratov, 2006. Puzikov, V.G., Person: Socio-cultural criteria of measurement, Nauka o Cheloveke: Gum. Issled., 2013, no. 4(14), pp. 111–118. Babenko, I.A., Institutionalization of human capital in the current socio-economic system of Russia, Cand. Sci. (Soc.) Dissertation, Belgorod, 2012. Danilkova, M.P., The concept of the value theory from the standpoint of dialectical methodology, Cand. Sci. (Philos.) Dissertation, Novosibirsk, 2008. Molodykh, E.N., Relationship of estimates of the organizational culture and attitudes of staff to comply with ethical standards of business behavior, Cand. Sci. (Psychol.) Dissertation, Moscow, 2009. Lebedeva, N.M. and Tatarko, A.N., Values and social capital as a basis for socio-economic development, Zh. Inst. Issled., 2010, vol. 2, no. 1, pp. 17–34. Samarina, I.S., Cultural capital of students in the conditions of Russia’s transition to the innovative type of development, Cand. Sci. (Econ.) Dissertation, Saratov, 2010. Astakhova, L.V., The concept of the information-security culture, Sci. Tech. Inf. Process., 2014, vol. 41, no. 1, pp. 22–28. Pirozhkova, N.I., Assessment of the human capital of the enterprise, Cand. Sci. (Econ.) Dissertation, Moscow, 2012. Tolstova, Yu.N., Izmerenie v sotsiologii: uchebnoe posobie (Measurement in Sociology: Textbook), Moscow: KDU, 2007. Zinov, V.G., Upravlenie intellektual’noi sobstvennost’yu (Intellectual Property Management), Moscow: Delo, 2003. Gaponenko, A.L. and Orlova, T.M., Upravlenie znaniyami: Kak prevratit’ znaniya v capital (Knowledge Management: How to Turn Knowledge into Capital), Moscow: Eksmo, 2008.