基于人为因素的网络安全准备模型

IF 2.9 4区 综合性期刊 Q2 MULTIDISCIPLINARY SCIENCES
Yusuf Taoheed Abiodun, Sajjad Mahmood, Mahmood Niazi, Mohammad Alshayeb, Azzah A. AlGhamdi
{"title":"基于人为因素的网络安全准备模型","authors":"Yusuf Taoheed Abiodun,&nbsp;Sajjad Mahmood,&nbsp;Mahmood Niazi,&nbsp;Mohammad Alshayeb,&nbsp;Azzah A. AlGhamdi","doi":"10.1007/s13369-025-10349-w","DOIUrl":null,"url":null,"abstract":"<div><p>Human error is one of the leading causes of data and security breaches, as cybersecurity attackers prey on psychological manipulations to push users into performing unwanted actions or providing information. Humans act as a weak link in cyberattacks, and as a result, organizations are prone to phishing, business email compromise, and malware types of cybersecurity attacks. In this study, we identify the human-centric barriers and success factors that influence an organization's readiness to handle cybersecurity threats. Moreover, we develop a readiness model to help organizations assess and implement security practices for cybersecurity from the human factor perspective. We conducted a multivocal literature review on 120 primary studies to identify human barriers, success factors, and best practices that positively influence cybersecurity. The results show that researchers consider trust, ignorance, and a lack of technological knowledge the significant obstacles, while industry practitioners point to a lack of technological knowledge, negligence, and impulsive or reckless behavior as the primary barriers. On the other hand, knowledge, proactive awareness, and cognitive ability are the most significant success factors from both researchers’ and industry practitioners’ perspectives. We mapped the identified barriers to the CyBOK cybersecurity knowledge areas. Next, we used the identified success factors to develop a cybersecurity readiness model. The readiness model was validated by applying it to a real-world scenario using the case studies approach. This paper provides a knowledge base to develop threat prevention strategies for human factors in cybersecurity and assist organizations in devising approaches to tackle pressing security issues.</p></div>","PeriodicalId":54354,"journal":{"name":"Arabian Journal for Science and Engineering","volume":"50 19","pages":"16199 - 16219"},"PeriodicalIF":2.9000,"publicationDate":"2025-06-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Cybersecurity Readiness Model Based on Human Factors\",\"authors\":\"Yusuf Taoheed Abiodun,&nbsp;Sajjad Mahmood,&nbsp;Mahmood Niazi,&nbsp;Mohammad Alshayeb,&nbsp;Azzah A. AlGhamdi\",\"doi\":\"10.1007/s13369-025-10349-w\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><p>Human error is one of the leading causes of data and security breaches, as cybersecurity attackers prey on psychological manipulations to push users into performing unwanted actions or providing information. Humans act as a weak link in cyberattacks, and as a result, organizations are prone to phishing, business email compromise, and malware types of cybersecurity attacks. In this study, we identify the human-centric barriers and success factors that influence an organization's readiness to handle cybersecurity threats. Moreover, we develop a readiness model to help organizations assess and implement security practices for cybersecurity from the human factor perspective. We conducted a multivocal literature review on 120 primary studies to identify human barriers, success factors, and best practices that positively influence cybersecurity. The results show that researchers consider trust, ignorance, and a lack of technological knowledge the significant obstacles, while industry practitioners point to a lack of technological knowledge, negligence, and impulsive or reckless behavior as the primary barriers. On the other hand, knowledge, proactive awareness, and cognitive ability are the most significant success factors from both researchers’ and industry practitioners’ perspectives. We mapped the identified barriers to the CyBOK cybersecurity knowledge areas. Next, we used the identified success factors to develop a cybersecurity readiness model. The readiness model was validated by applying it to a real-world scenario using the case studies approach. This paper provides a knowledge base to develop threat prevention strategies for human factors in cybersecurity and assist organizations in devising approaches to tackle pressing security issues.</p></div>\",\"PeriodicalId\":54354,\"journal\":{\"name\":\"Arabian Journal for Science and Engineering\",\"volume\":\"50 19\",\"pages\":\"16199 - 16219\"},\"PeriodicalIF\":2.9000,\"publicationDate\":\"2025-06-19\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Arabian Journal for Science and Engineering\",\"FirstCategoryId\":\"103\",\"ListUrlMain\":\"https://link.springer.com/article/10.1007/s13369-025-10349-w\",\"RegionNum\":4,\"RegionCategory\":\"综合性期刊\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q2\",\"JCRName\":\"MULTIDISCIPLINARY SCIENCES\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Arabian Journal for Science and Engineering","FirstCategoryId":"103","ListUrlMain":"https://link.springer.com/article/10.1007/s13369-025-10349-w","RegionNum":4,"RegionCategory":"综合性期刊","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"MULTIDISCIPLINARY SCIENCES","Score":null,"Total":0}
引用次数: 0

摘要

人为错误是导致数据和安全漏洞的主要原因之一,因为网络安全攻击者利用心理操纵,迫使用户执行不必要的操作或提供信息。在网络攻击中,人是一个薄弱环节,因此,组织容易受到网络钓鱼、商业电子邮件泄露和恶意软件类型的网络安全攻击。在本研究中,我们确定了影响组织应对网络安全威胁准备的以人为中心的障碍和成功因素。此外,我们开发了一个准备模型,以帮助组织从人为因素的角度评估和实施网络安全实践。我们对120项主要研究进行了多语种文献综述,以确定积极影响网络安全的人为障碍、成功因素和最佳实践。研究结果表明,研究人员认为信任、无知和缺乏技术知识是主要障碍,而行业从业者则认为缺乏技术知识、疏忽和冲动或鲁莽行为是主要障碍。另一方面,从研究人员和行业从业者的角度来看,知识、主动意识和认知能力是最重要的成功因素。我们将识别的障碍映射到CyBOK网络安全知识领域。接下来,我们使用确定的成功因素来开发网络安全准备模型。准备模型通过使用案例研究方法将其应用于实际场景来验证。本文提供了一个知识库,用于开发针对网络安全中的人为因素的威胁预防策略,并协助组织设计解决紧迫安全问题的方法。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Cybersecurity Readiness Model Based on Human Factors

Human error is one of the leading causes of data and security breaches, as cybersecurity attackers prey on psychological manipulations to push users into performing unwanted actions or providing information. Humans act as a weak link in cyberattacks, and as a result, organizations are prone to phishing, business email compromise, and malware types of cybersecurity attacks. In this study, we identify the human-centric barriers and success factors that influence an organization's readiness to handle cybersecurity threats. Moreover, we develop a readiness model to help organizations assess and implement security practices for cybersecurity from the human factor perspective. We conducted a multivocal literature review on 120 primary studies to identify human barriers, success factors, and best practices that positively influence cybersecurity. The results show that researchers consider trust, ignorance, and a lack of technological knowledge the significant obstacles, while industry practitioners point to a lack of technological knowledge, negligence, and impulsive or reckless behavior as the primary barriers. On the other hand, knowledge, proactive awareness, and cognitive ability are the most significant success factors from both researchers’ and industry practitioners’ perspectives. We mapped the identified barriers to the CyBOK cybersecurity knowledge areas. Next, we used the identified success factors to develop a cybersecurity readiness model. The readiness model was validated by applying it to a real-world scenario using the case studies approach. This paper provides a knowledge base to develop threat prevention strategies for human factors in cybersecurity and assist organizations in devising approaches to tackle pressing security issues.

求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
Arabian Journal for Science and Engineering
Arabian Journal for Science and Engineering MULTIDISCIPLINARY SCIENCES-
CiteScore
5.70
自引率
3.40%
发文量
993
期刊介绍: King Fahd University of Petroleum & Minerals (KFUPM) partnered with Springer to publish the Arabian Journal for Science and Engineering (AJSE). AJSE, which has been published by KFUPM since 1975, is a recognized national, regional and international journal that provides a great opportunity for the dissemination of research advances from the Kingdom of Saudi Arabia, MENA and the world.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信