Enhancing Cybersecurity Awareness Training: A Comprehensive Phishing Exercise Approach

Enhancing Cybersecurity Awareness Training: A Comprehensive Phishing Exercise Approach
复制标题

加强网络安全意识培训:综合网络钓鱼练习方法

DOI:
--
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
Michael J. A. Miranda
Michael J. A. Miranda
中科院分区:
--
文献类型:
--
作者:
Michael J. A. Miranda

文献摘要

被引文献

相似文献

[摘要]电子邮件通信几乎在商业和个人活动的各个方面都是一项重要的服务。一个人的电子邮件地址是最依赖于可靠和负责任的通信的在线身份。在大多数情况下,在线进行的银行、健康和娱乐活动取决于一个人拥有并积极维护一个电子邮件地址。不幸的是,电子邮件本身具有安全缺陷,使恶意行为者能够通过网络钓鱼电子邮件进行欺诈。技术解决方案并不能完全解决这个问题,用户本身需要接受培训,了解如何识别和响应可疑的网络钓鱼电子邮件。结构化和全面的网络钓鱼演习培训计划可以(1)降低源自欺诈性电子邮件的网络安全危害的可能性;(2)改善整体网络安全态势。
[Abstract] Email communications is a critical service in nearly every aspect of business and personal activities. A person’s email address is the online identity most relied upon for reliable and accountable communications. Banking, health and recreational activities conducted online in most cases depend on a person possessing and actively maintaining an email address. Unfortunately, email inherently possesses security shortcomings that enable malicious actors to commit fraud through phishing emails. Technology solutions do not entirely solve this issue, and the users themselves require training on how to identify and respond to suspected phishing emails. A structured and comprehensive phishing exercise training program can (1) reduce the probability of a cybersecurity compromise originating from fraudulent emails and (2) improve the overall cybersecurity posture.