TY - GEN
T1 - Social network theoretic framework for organizational social engineering susceptibility index
AU - Gupta, Manish
AU - Sharman, Raj
PY - 2006
Y1 - 2006
N2 - Social Engineering is an undeniable and pervasive threat to the security of information systems of an organization due to its reliance on social nature of human beings. Social engineering uses dynamic art of manipulating social behavior of human relationships to obtain unauthorized and privileged information. Corporations have pressing need to design and implement reasonable countermeasures and controls to effectively mitigate social engineering attacks. In this paper, we propose a framework for development of social engineering susceptibility index (SESI) that reveals real risks from social engineering attack that an organization's employees are exposed to. Risk managers can compute the SESI index, which is based on social network theory propositions, to understand risk exposure of a critical group of individuals or organizational departments to proactively engage in elevating security measures. The framework equips risk managers with an understanding to design better security decisions and proper policies and measures to reduce risk.
AB - Social Engineering is an undeniable and pervasive threat to the security of information systems of an organization due to its reliance on social nature of human beings. Social engineering uses dynamic art of manipulating social behavior of human relationships to obtain unauthorized and privileged information. Corporations have pressing need to design and implement reasonable countermeasures and controls to effectively mitigate social engineering attacks. In this paper, we propose a framework for development of social engineering susceptibility index (SESI) that reveals real risks from social engineering attack that an organization's employees are exposed to. Risk managers can compute the SESI index, which is based on social network theory propositions, to understand risk exposure of a critical group of individuals or organizational departments to proactively engage in elevating security measures. The framework equips risk managers with an understanding to design better security decisions and proper policies and measures to reduce risk.
KW - Insider attacks
KW - Organizational security
KW - Social engineering
KW - Social network theory
KW - Social networks
KW - Susceptibility index
UR - https://www.scopus.com/pages/publications/84870309152
M3 - Conference contribution
AN - SCOPUS:84870309152
SN - 9781604236262
T3 - Association for Information Systems - 12th Americas Conference On Information Systems, AMCIS 2006
SP - 3371
EP - 3381
BT - Association for Information Systems - 12th Americas Conference On Information Systems, AMCIS 2006
T2 - 12th Americas Conference on Information Systems, AMCIS 2006
Y2 - 4 August 2006 through 6 August 2006
ER -