Social engineering framework: understanding the deception strategy to control human element of information security system
Social engineering has become serious phenomenon in the history of information security worldwide. Although this approach is widely used by criminals to exploit the human aspect as the security weakest link, there is not many studies focusing on such issue. Fail to understand the nature of social engineering will increase the security risk posture of the organisation. In spite of the fact that most of social engineering attacks are seemed to be unstructure and diverse in nature, this study shows that there exists common patterns that can be mapped and organised in a logical way. This social engineering framework can help security practitioners to understand the nature and characteristics of such attack. By understanding the detail characteristics of social engineering, a holistic risk mitigation strategic framework can be developed in a systemic way. This concept shall be used by the management of organisation or institution in developing its security mitigation strategy.
M00285 | (Rack Thesis) | Available |
No other version available