论文标题
中小型企业机密问题和采用良好的网络安全实践
SMEs Confidentiality Issues and Adoption of Good Cybersecurity Practices
论文作者
论文摘要
中小型企业(SME)被认为更容易受到网络攻击的影响。但是,基于中小型企业的特征,它们不采用良好的网络安全实践。为了解决中小企业安全采用问题,我们正在设计自己动手(DIY)安全评估和能力改进方法,Cysec。在CYSEC的首次验证中,我们在四个中小型企业中进行了一项多案例研究。我们观察到,机密性问题可能会影响用户为CYSEC提供相关和准确的安全信息的决策。缺乏精确的信息可能会影响我们提供准确建议的DIY评估方法。在本文中,我们探讨了动态同意的重要性及其对中小企业信任感知和共享信息的影响。我们讨论缺乏信任感知可以通过应用动态同意来解决。最后,我们描述了与中小企业的三次访谈的结果,并介绍了CYSEC中新的沟通方式如何帮助我们了解中小企业对共享信息的更好态度。
Small and medium-sized enterprises (SME) are considered more vulnerable to cyber-attacks. However, and based on SMEs characteristics, they do not adopt good cybersecurity practices. To address the SMEs security adoption problem, we are designing a do-it-yourself (DIY) security assessment and capability improvement method, CYSEC. In the first validation of CYSEC, we conducted a multi-case study in four SMEs. We observed that confidentiality concerns could influence users decisions to provide CYSEC with relevant and accurate security information. The lack of precise information may impact our DIY assessment method to provide accurate recommendations. In this paper, we explore the importance of dynamic consent and its effect on SMEs trust perception and sharing information. We discuss the lack of trust perception may be addressed by applying dynamic consent. Finally, we describe the results of three interviews with SMEs and present how the new way of communication in CYSEC can help us to understand better SMEs attitudes towards sharing information.