An insider threat for companies is defined as a threat caused by malicious user
who is an employee company. In recent years, there are number of work on
insider threats in information security technologies. These works shows that
companies should increasingly and seriously should take into account these
threats. Human factors in companies constitute one of the weakest links in
information security technology and its products used in human resource (HR)
management departments. In the literature, insider threats are generally classified
into two main categories: 1) Intentional insider threats and 2) Unintentional
insider threats.
In this work, we address the employees working in HR departments of various
companies from different sectors. Since HR departments are one of the critical
departments for insider threats, we focus on the scenario that a malicious insider
accesses critical, important and/or personal data. In this scenario, a malicious
employee of HR department may change or misuse of the data belonging to
his/her company (product data, marketing data, strategy documents etc.) and/or
the data belonging to the other employees (e-mails, ID numbers, birth dates,
salaries, health data etc.) by intentionally or unintentionally.
By taking into account the previous works done in the literature, we prepare new
questionnaire for this work. The questionnaire is applied to HR managers and
employees of various sectors. Our aim is to increase HR managers and HR
employees awareness of insider information security threats.
Information Security Insider Threats Human Resource Department
Diğer ID | JA49TN35VK |
---|---|
Bölüm | Makaleler |
Yazarlar | |
Yayımlanma Tarihi | 1 Haziran 2012 |
Yayımlandığı Sayı | Yıl 2012 Cilt: 4 Sayı: 1 |