Cyber Security Culture: Counteracting Cyber Threats through Organizational Learning and Training
暫譯: 網路安全文化:透過組織學習與訓練對抗網路威脅
Peter Trim, David Upton
商品描述
Focusing on countermeasures against orchestrated cyber-attacks, Cyber Security Culture is research-based and reinforced with insights from experts who do not normally release information into the public arena. It will enable managers of organizations across different industrial sectors and government agencies to better understand how organizational learning and training can be utilized to develop a culture that ultimately protects an organization from attacks. Peter Trim and David Upton believe that the speed and complexity of cyber-attacks demand a different approach to security management, including scenario-based planning and training, to supplement security policies and technical protection systems. The authors provide in-depth understanding of how organizational learning can produce cultural change addressing the behaviour of individuals, as well as machines. They provide information to help managers form policy to prevent cyber intrusions, to put robust security systems and procedures in place and to arrange appropriate training interventions such as table top exercises. Guidance embracing current and future threats and addressing issues such as social engineering is included. Although the work is embedded in a theoretical framework, non-technical staff will find the book of practical use because it renders highly technical subjects accessible and links firmly with areas beyond ICT, such as human resource management - in relation to bridging the education/training divide and allowing organizational learning to be embraced. This book will interest Government officials, policy advisors, law enforcement officers and senior managers within companies, as well as academics and students in a range of disciplines including management and computer science.
商品描述(中文翻譯)
專注於對策以應對協調的網路攻擊,《網路安全文化》是基於研究的,並結合了通常不會公開資訊的專家的見解。這本書將使來自不同產業部門和政府機構的管理者更好地理解如何利用組織學習和訓練來發展一種最終能保護組織免受攻擊的文化。彼得·特里姆(Peter Trim)和大衛·厄普頓(David Upton)認為,網路攻擊的速度和複雜性要求對安全管理採取不同的方法,包括基於情境的規劃和訓練,以補充安全政策和技術保護系統。
作者深入探討了組織學習如何促進文化變革,影響個體和機器的行為。他們提供資訊以幫助管理者制定政策以防止網路入侵,建立健全的安全系統和程序,並安排適當的訓練介入,例如桌上演練。書中還包括針對當前和未來威脅的指導,並處理社會工程等問題。
儘管這部作品嵌入於理論框架中,非技術人員仍會發現這本書具有實用性,因為它使高度技術性的主題變得易於理解,並與超越資訊與通信技術(ICT)的領域緊密相連,例如人力資源管理——在縮小教育/訓練差距和促進組織學習方面。這本書將吸引政府官員、政策顧問、執法官員和公司高層管理者,以及管理學和計算機科學等多個學科的學者和學生。