Information Security Competency Evaluation Model for Internal Staff

Yu-peng LIU,Shi-you QU
DOI: https://doi.org/10.3969/j.issn.1007-3221.2014.01.021
2014-01-01
Abstract:In recent years , more and more evidence shows that the security of information systems and information management within the organization is a major security risk .Therefore , it is particularly urgent and important that internal staff shall be evaluated and a staff competenly information security responsibility is found to eliminate internal attack behaviours of employees and ensure the security of information systems and information manage-ment.Consequently information security competency evaluation for internal staff is an important issue .Under the analysis of the characteristics of the aggressive behavior from internal staff and a comprehensive summary of the competency research , internal staff information security competency evaluation index system is built .On this base , organization internal staff information security competency evaluation model is proposed .Based on safety and risk prevention thinking , the model divides the evaluation into two stages and takes into account the person-ality advantage of the decision makers in decision-making preferences and individuality advantage , which more realistically reflects the difference between the team members .Finally, the effectiveness and practicality of the evaluation model is verified through case analysis .
What problem does this paper attempt to address?