Auditing the Human Factor as a Part of Setting up an Information Security Management System

The human factor is the weakest link in all information systems regarding security but the users are not aware of the risks and the importance of following policies and routines to prevent a security breach. The most common attack vector starts by exploiting the human weakness and plant malware insi...

Full description

Bibliographic Details
Main Author: Svensson, Gustav
Format: Others
Language:English
Published: KTH, Industriella informations- och styrsystem 2013
Online Access:http://urn.kb.se/resolve?urn=urn:nbn:se:kth:diva-119528
id ndltd-UPSALLA1-oai-DiVA.org-kth-119528
record_format oai_dc
spelling ndltd-UPSALLA1-oai-DiVA.org-kth-1195282013-06-11T04:05:37ZAuditing the Human Factor as a Part of Setting up an Information Security Management SystemengSvensson, GustavKTH, Industriella informations- och styrsystem2013The human factor is the weakest link in all information systems regarding security but the users are not aware of the risks and the importance of following policies and routines to prevent a security breach. The most common attack vector starts by exploiting the human weakness and plant malware inside the organization. There is a need to nd a good way to audit the human factor to address this issue. Dierent penetration tests will be evaluated in this study; two phishing attacks and one in the form of a survey under a false pretext. The respondents are tricked into thinking that they are answering questions about customer service eciency while they are actually about information security and social engineering. This thesis argues that it is very complicated to measure people's predisposition to fall for social engineering but the survey under a false pretext is an interesting method to use when auditing how vulnerable an organization is to social engineering. It is also good at increasing the security awareness and to be used as a soft-start for the information security management process. The author also argues that all humans can be deceived and trust is something that is crucial for the society to work. It is therefore perhaps more meaningful to audit the users compliance with security policies and not the human behavior. Student thesisinfo:eu-repo/semantics/bachelorThesistexthttp://urn.kb.se/resolve?urn=urn:nbn:se:kth:diva-119528EES Examensarbete / Master Thesis ; XR-EE_ICS 2013:001application/pdfinfo:eu-repo/semantics/openAccess
collection NDLTD
language English
format Others
sources NDLTD
description The human factor is the weakest link in all information systems regarding security but the users are not aware of the risks and the importance of following policies and routines to prevent a security breach. The most common attack vector starts by exploiting the human weakness and plant malware inside the organization. There is a need to nd a good way to audit the human factor to address this issue. Dierent penetration tests will be evaluated in this study; two phishing attacks and one in the form of a survey under a false pretext. The respondents are tricked into thinking that they are answering questions about customer service eciency while they are actually about information security and social engineering. This thesis argues that it is very complicated to measure people's predisposition to fall for social engineering but the survey under a false pretext is an interesting method to use when auditing how vulnerable an organization is to social engineering. It is also good at increasing the security awareness and to be used as a soft-start for the information security management process. The author also argues that all humans can be deceived and trust is something that is crucial for the society to work. It is therefore perhaps more meaningful to audit the users compliance with security policies and not the human behavior.
author Svensson, Gustav
spellingShingle Svensson, Gustav
Auditing the Human Factor as a Part of Setting up an Information Security Management System
author_facet Svensson, Gustav
author_sort Svensson, Gustav
title Auditing the Human Factor as a Part of Setting up an Information Security Management System
title_short Auditing the Human Factor as a Part of Setting up an Information Security Management System
title_full Auditing the Human Factor as a Part of Setting up an Information Security Management System
title_fullStr Auditing the Human Factor as a Part of Setting up an Information Security Management System
title_full_unstemmed Auditing the Human Factor as a Part of Setting up an Information Security Management System
title_sort auditing the human factor as a part of setting up an information security management system
publisher KTH, Industriella informations- och styrsystem
publishDate 2013
url http://urn.kb.se/resolve?urn=urn:nbn:se:kth:diva-119528
work_keys_str_mv AT svenssongustav auditingthehumanfactorasapartofsettingupaninformationsecuritymanagementsystem
_version_ 1716588945906597888