学术机构的资讯安全

Steffani A. Burd, Scott Cherkin, J. Concannon
{"title":"学术机构的资讯安全","authors":"Steffani A. Burd, Scott Cherkin, J. Concannon","doi":"10.1300/J460v01n02_05","DOIUrl":null,"url":null,"abstract":"Abstract Academic institutions face unique information security threats as well as increasingly frequent and severe incidents, yet they have invested relatively few resources to define and address these issues. Incidents such as information theft, data tampering, viruses, worms, and terrorist activity constitute significant threats to the security of academic institutions. Adverse impacts on academic institutions and the general public include compromised private data, potential attacks on U.S. critical infrastructure, and substantial financial losses. Strategies to remediate these issues must be identified, developed and implemented to curb the trend of increasingly frequent and severe information security incidents as well as the damage they incur. The purpose of this article is to define these emerging information security issues and to propose strategies to remediate them. First, empirically based knowledge of information security in academic institutions must be developed and shared, including quantification of issues, use of appropriate metrics, and identification of best and worst practices. Second, policies for information security must be developed, promulgated and implemented. These policies must balance learning, experimentation, and openness with adequate security measures. Third, the current narrow and fragmented approach to information security practices must be expanded to a holistic, integrated view and the current reactive stance must be changed to a proactive, prescriptive orientation toward information security. Directions for future research, suggestions for policy and practice, and recommendations for information sharing between universities, research institutions, government and law enforcement are provided.","PeriodicalId":345897,"journal":{"name":"Journal of Security Education","volume":"15 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2005-03-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"Information Security in Academic Institutions\",\"authors\":\"Steffani A. Burd, Scott Cherkin, J. Concannon\",\"doi\":\"10.1300/J460v01n02_05\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Abstract Academic institutions face unique information security threats as well as increasingly frequent and severe incidents, yet they have invested relatively few resources to define and address these issues. Incidents such as information theft, data tampering, viruses, worms, and terrorist activity constitute significant threats to the security of academic institutions. Adverse impacts on academic institutions and the general public include compromised private data, potential attacks on U.S. critical infrastructure, and substantial financial losses. Strategies to remediate these issues must be identified, developed and implemented to curb the trend of increasingly frequent and severe information security incidents as well as the damage they incur. The purpose of this article is to define these emerging information security issues and to propose strategies to remediate them. First, empirically based knowledge of information security in academic institutions must be developed and shared, including quantification of issues, use of appropriate metrics, and identification of best and worst practices. Second, policies for information security must be developed, promulgated and implemented. These policies must balance learning, experimentation, and openness with adequate security measures. Third, the current narrow and fragmented approach to information security practices must be expanded to a holistic, integrated view and the current reactive stance must be changed to a proactive, prescriptive orientation toward information security. Directions for future research, suggestions for policy and practice, and recommendations for information sharing between universities, research institutions, government and law enforcement are provided.\",\"PeriodicalId\":345897,\"journal\":{\"name\":\"Journal of Security Education\",\"volume\":\"15 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2005-03-03\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Journal of Security Education\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1300/J460v01n02_05\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Security Education","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1300/J460v01n02_05","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

学术机构面临着独特的信息安全威胁以及日益频繁和严重的事件,但它们投入的资源相对较少,无法对这些问题进行定义和解决。信息盗窃、数据篡改、病毒、蠕虫和恐怖活动等事件对学术机构的安全构成重大威胁。对学术机构和公众的不利影响包括私人数据泄露、对美国关键基础设施的潜在攻击以及重大的经济损失。我们必须制订和实施策略,以遏止资讯保安事件日益频繁和严重的趋势,以及它们所造成的损害。本文的目的是定义这些新出现的信息安全问题,并提出解决这些问题的策略。首先,必须开发和共享学术机构中基于经验的信息安全知识,包括问题的量化、适当度量的使用以及最佳和最差实践的识别。第二,必须制定、颁布和实施信息安全政策。这些政策必须在学习、实验和开放与适当的安全措施之间取得平衡。第三,当前信息安全实践中狭隘、碎片化的做法必须扩展到整体、综合的观点,当前被动的立场必须改变为主动、规范的信息安全取向。提出了今后的研究方向、政策和实践建议以及高校、科研机构、政府和执法部门之间信息共享的建议。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Information Security in Academic Institutions
Abstract Academic institutions face unique information security threats as well as increasingly frequent and severe incidents, yet they have invested relatively few resources to define and address these issues. Incidents such as information theft, data tampering, viruses, worms, and terrorist activity constitute significant threats to the security of academic institutions. Adverse impacts on academic institutions and the general public include compromised private data, potential attacks on U.S. critical infrastructure, and substantial financial losses. Strategies to remediate these issues must be identified, developed and implemented to curb the trend of increasingly frequent and severe information security incidents as well as the damage they incur. The purpose of this article is to define these emerging information security issues and to propose strategies to remediate them. First, empirically based knowledge of information security in academic institutions must be developed and shared, including quantification of issues, use of appropriate metrics, and identification of best and worst practices. Second, policies for information security must be developed, promulgated and implemented. These policies must balance learning, experimentation, and openness with adequate security measures. Third, the current narrow and fragmented approach to information security practices must be expanded to a holistic, integrated view and the current reactive stance must be changed to a proactive, prescriptive orientation toward information security. Directions for future research, suggestions for policy and practice, and recommendations for information sharing between universities, research institutions, government and law enforcement are provided.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信