Evidential Reasoning Approach to Behavioural Analysis of ICT Users’ Security Awareness
The role of ICT system’s user should be taken into consideration when developing different information security solutions because user, as its constitutive element, can significantly affect overall system security with his/her potentially risky behaviour depending on the level of user’s security awa...
Main Authors: | , , |
---|---|
Format: | Article |
Language: | English |
Published: |
Faculty of Mechanical Engineering in Slavonski Brod, Faculty of Electrical Engineering in Osijek, Faculty of Civil Engineering in Osijek
2018-01-01
|
Series: | Tehnički Vjesnik |
Subjects: | |
Online Access: | https://hrcak.srce.hr/file/293182 |
_version_ | 1797207658155999232 |
---|---|
author | Tomislav Galba Kresimir Solic Kresimir Nenadic |
author_facet | Tomislav Galba Kresimir Solic Kresimir Nenadic |
author_sort | Tomislav Galba |
collection | DOAJ |
description | The role of ICT system’s user should be taken into consideration when developing different information security solutions because user, as its constitutive element, can significantly affect overall system security with his/her potentially risky behaviour depending on the level of user’s security awareness. In this paper authors propose risk assessment approach of ICT users’ behaviour based on the evidential reasoning technique. Performance testing was compared using combination of cluster analysis and discriminant analysis while empirical analysis was conducted on the total of 627 e-mail users grouped regarding gender, age, technical background knowledge and level of experience. Assessment methodology used in this paper has proven to be well suited for evaluation of users’ awareness and identification of their potentially risky behaviour. Results of empirical analysis showed that all groups of users got overall utility grade higher than the simulated "minimally enough aware" user, but less than “average awareness” grade. As users of all groups are highly critical towards collocutor, it can mean that users are quite aware about the importance of information security foundation, but also about lack of knowledge regarding different security issues. Another possible reason may be the users’ negligence toward security guidelines and protocols. |
first_indexed | 2024-04-24T09:26:24Z |
format | Article |
id | doaj.art-1b8fe15c315c4f0a96d5533189e10a8c |
institution | Directory Open Access Journal |
issn | 1330-3651 1848-6339 |
language | English |
last_indexed | 2024-04-24T09:26:24Z |
publishDate | 2018-01-01 |
publisher | Faculty of Mechanical Engineering in Slavonski Brod, Faculty of Electrical Engineering in Osijek, Faculty of Civil Engineering in Osijek |
record_format | Article |
series | Tehnički Vjesnik |
spelling | doaj.art-1b8fe15c315c4f0a96d5533189e10a8c2024-04-15T14:43:05ZengFaculty of Mechanical Engineering in Slavonski Brod, Faculty of Electrical Engineering in Osijek, Faculty of Civil Engineering in OsijekTehnički Vjesnik1330-36511848-63392018-01-0125230931510.17559/TV-20150513123751Evidential Reasoning Approach to Behavioural Analysis of ICT Users’ Security AwarenessTomislav Galba0Kresimir Solic1Kresimir Nenadic2Faculty of Electrical Engineering, Computer Science and Information Technology Osijek, J. J. Strossmayer University of Osijek, Kneza Trpimira 2b, 31000 Osijek, CroatiaFaculty of Medicine, J. J. Strossmayer University of Osijek, Cara Hadrijana 10/E, 31000 Osijek, CroatiaFaculty of Electrical Engineering, Computer Science and Information Technology Osijek, J. J. Strossmayer University of Osijek, Kneza Trpimira 2b, 31000 Osijek, CroatiaThe role of ICT system’s user should be taken into consideration when developing different information security solutions because user, as its constitutive element, can significantly affect overall system security with his/her potentially risky behaviour depending on the level of user’s security awareness. In this paper authors propose risk assessment approach of ICT users’ behaviour based on the evidential reasoning technique. Performance testing was compared using combination of cluster analysis and discriminant analysis while empirical analysis was conducted on the total of 627 e-mail users grouped regarding gender, age, technical background knowledge and level of experience. Assessment methodology used in this paper has proven to be well suited for evaluation of users’ awareness and identification of their potentially risky behaviour. Results of empirical analysis showed that all groups of users got overall utility grade higher than the simulated "minimally enough aware" user, but less than “average awareness” grade. As users of all groups are highly critical towards collocutor, it can mean that users are quite aware about the importance of information security foundation, but also about lack of knowledge regarding different security issues. Another possible reason may be the users’ negligence toward security guidelines and protocols.https://hrcak.srce.hr/file/293182behavioural analysiscluster analysisevidential reasoning approachinformation securityusers’ awareness |
spellingShingle | Tomislav Galba Kresimir Solic Kresimir Nenadic Evidential Reasoning Approach to Behavioural Analysis of ICT Users’ Security Awareness Tehnički Vjesnik behavioural analysis cluster analysis evidential reasoning approach information security users’ awareness |
title | Evidential Reasoning Approach to Behavioural Analysis of ICT Users’ Security Awareness |
title_full | Evidential Reasoning Approach to Behavioural Analysis of ICT Users’ Security Awareness |
title_fullStr | Evidential Reasoning Approach to Behavioural Analysis of ICT Users’ Security Awareness |
title_full_unstemmed | Evidential Reasoning Approach to Behavioural Analysis of ICT Users’ Security Awareness |
title_short | Evidential Reasoning Approach to Behavioural Analysis of ICT Users’ Security Awareness |
title_sort | evidential reasoning approach to behavioural analysis of ict users security awareness |
topic | behavioural analysis cluster analysis evidential reasoning approach information security users’ awareness |
url | https://hrcak.srce.hr/file/293182 |
work_keys_str_mv | AT tomislavgalba evidentialreasoningapproachtobehaviouralanalysisofictuserssecurityawareness AT kresimirsolic evidentialreasoningapproachtobehaviouralanalysisofictuserssecurityawareness AT kresimirnenadic evidentialreasoningapproachtobehaviouralanalysisofictuserssecurityawareness |