Towards metamodel-based approach for Information Security Awareness Management

Information technology and information system have been used widely in many fields such as in business, education, marketing, transportation and medical. Security aspect plays a vital role and thus turns into a challenging issue. The security should be readily installed and resistance to various num...

Full description

Saved in:
Bibliographic Details
Main Authors: Jama, A. Y., Siraj, M. M., Kadir, R.
Format: Conference or Workshop Item
Language:English
Published: Institute of Electrical and Electronics Engineers Inc. 2015
Subjects:
Online Access:http://eprints.utm.my/id/eprint/59529/1/AhmedYousufJama2014_TowardsMetamodelBasedApproach.pdf
http://eprints.utm.my/id/eprint/59529/
http://dx.doi.org/10.1109/ISBAST.2014.7013141
Tags: Add Tag
No Tags, Be the first to tag this record!
id my.utm.59529
record_format eprints
spelling my.utm.595292021-08-01T04:21:24Z http://eprints.utm.my/id/eprint/59529/ Towards metamodel-based approach for Information Security Awareness Management Jama, A. Y. Siraj, M. M. Kadir, R. QA75 Electronic computers. Computer science Information technology and information system have been used widely in many fields such as in business, education, marketing, transportation and medical. Security aspect plays a vital role and thus turns into a challenging issue. The security should be readily installed and resistance to various numbers of potential attacks likes Spyware, Phishing / Spam and Malwares (Virus, Worm and Trojans). It is important to have specific countermeasures that could minimize the harm to enterprises. Thus, increasing the awareness to optimal level is the main target of enterprise management. Unfortunately, the main reason that fails many existing enterprise' Information Security Awareness Management (ISAM) models is the complexity and inflexibility. Complexity means the model's structure is less practical (for instance, the implementation needs to be deployed manually). Inflexibility means it cannot support multiple kinds of businesses and did not consider security aspects. In this paper, we surveyed and discussed several existing ISAM models considering the security issues in current enterprise. We proposed a metamodel-based approach for ISAM that can offer efficiency and security that brings out clearly significant benefits by highlighting the organization overall level of awareness whether it is strong enough or weak. This will help many users in this domain to easily understand the important concepts required for their own information security awareness management. Institute of Electrical and Electronics Engineers Inc. 2015 Conference or Workshop Item PeerReviewed application/pdf en http://eprints.utm.my/id/eprint/59529/1/AhmedYousufJama2014_TowardsMetamodelBasedApproach.pdf Jama, A. Y. and Siraj, M. M. and Kadir, R. (2015) Towards metamodel-based approach for Information Security Awareness Management. In: 2014 4th International Symposium on Biometrics and Security Technologies, ISBAST 2014, 26-27 Aug 2014, Kuala Lumpur, Malaysia. http://dx.doi.org/10.1109/ISBAST.2014.7013141
institution Universiti Teknologi Malaysia
building UTM Library
collection Institutional Repository
continent Asia
country Malaysia
content_provider Universiti Teknologi Malaysia
content_source UTM Institutional Repository
url_provider http://eprints.utm.my/
language English
topic QA75 Electronic computers. Computer science
spellingShingle QA75 Electronic computers. Computer science
Jama, A. Y.
Siraj, M. M.
Kadir, R.
Towards metamodel-based approach for Information Security Awareness Management
description Information technology and information system have been used widely in many fields such as in business, education, marketing, transportation and medical. Security aspect plays a vital role and thus turns into a challenging issue. The security should be readily installed and resistance to various numbers of potential attacks likes Spyware, Phishing / Spam and Malwares (Virus, Worm and Trojans). It is important to have specific countermeasures that could minimize the harm to enterprises. Thus, increasing the awareness to optimal level is the main target of enterprise management. Unfortunately, the main reason that fails many existing enterprise' Information Security Awareness Management (ISAM) models is the complexity and inflexibility. Complexity means the model's structure is less practical (for instance, the implementation needs to be deployed manually). Inflexibility means it cannot support multiple kinds of businesses and did not consider security aspects. In this paper, we surveyed and discussed several existing ISAM models considering the security issues in current enterprise. We proposed a metamodel-based approach for ISAM that can offer efficiency and security that brings out clearly significant benefits by highlighting the organization overall level of awareness whether it is strong enough or weak. This will help many users in this domain to easily understand the important concepts required for their own information security awareness management.
format Conference or Workshop Item
author Jama, A. Y.
Siraj, M. M.
Kadir, R.
author_facet Jama, A. Y.
Siraj, M. M.
Kadir, R.
author_sort Jama, A. Y.
title Towards metamodel-based approach for Information Security Awareness Management
title_short Towards metamodel-based approach for Information Security Awareness Management
title_full Towards metamodel-based approach for Information Security Awareness Management
title_fullStr Towards metamodel-based approach for Information Security Awareness Management
title_full_unstemmed Towards metamodel-based approach for Information Security Awareness Management
title_sort towards metamodel-based approach for information security awareness management
publisher Institute of Electrical and Electronics Engineers Inc.
publishDate 2015
url http://eprints.utm.my/id/eprint/59529/1/AhmedYousufJama2014_TowardsMetamodelBasedApproach.pdf
http://eprints.utm.my/id/eprint/59529/
http://dx.doi.org/10.1109/ISBAST.2014.7013141
_version_ 1707765858121547776
score 13.211869