Social engineering in information assurance curricula

Social engineering in information assurance curricula
复制标题

信息保障课程中的社会工程

DOI:
--
复制
发表时间:
2006
期刊:
Annual Conference on Information Security Curriculum Development
影响因子:
--
通讯作者:
Douglas P. Twitchell
Douglas P. Twitchell
中科院分区:
--
文献类型:
--
作者:
Douglas P. Twitchell

文献摘要

被引文献

相似文献

随着越来越多地使用安全技术,技术攻击应该变得更加困难,导致攻击者使用社会工程作为获取对信息的未经授权访问的手段。因此,社会工程对信息安全是一个潜在的危险威胁。幸运的是,已经提出了一些防范措施。这些对策包括实施策略、提供最终用户和关键人员教育以及执行安全审计。然而,目前大多数突出的信息保障课程并没有直接涉及社会工程,而只是间接地涉及对策。修改这些课程,将社会工程作为一个主题,可以帮助学生更好地准备面对社会工程威胁。
With the increasing use of security technology, technical attacks should become more difficult leading attackers to employ social engineering as a means to obtaining unauthorized access to information. Therefore, social engineering is a potentially dangerous threat to information security. Fortunately, a number of countermeasures have been proposed to defend against it. These countermeasures include implementing policy, providing end-user and key personnel education, and performing security audits. However, most current prominent information assurance curricula do not directly address social engineering and only indirectly address the countermeasures. Amending these curricula to include social engineering as a topic may help students be better prepared for encountering social engineering threats.