Towards an Enhancement of Organizational Information Security through Threat Factor Profiling (TFP) Model

Information security has been identified by organizations as part of internal operations that need to be well implemented and protected. This is because each day the organizations face a high probability of increase of threats to their networks and services that will lead to information security iss...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Veröffentlicht in:Journal of physics. Conference series 2017-09, Vol.892 (1), p.12011
Hauptverfasser: Sidi, Fatimah, Daud, Maslina, Ahmad, Sabariah, Zainuddin, Naqliyah, Anneisa Abdullah, Syafiqa, Jabar, Marzanah A., Suriani Affendey, Lilly, Ishak, Iskandar, Mohd Sharef, Nurfadhlina, Zolkepli, Maslina, Nur Majdina Nordin, Fatin, Amat Sejani, Hashimah, Ramadzan Hairani, Saiful
Format: Artikel
Sprache:eng
Schlagworte:
Online-Zugang:Volltext
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:Information security has been identified by organizations as part of internal operations that need to be well implemented and protected. This is because each day the organizations face a high probability of increase of threats to their networks and services that will lead to information security issues. Thus, effective information security management is required in order to protect their information assets. Threat profiling is a method that can be used by an organization to address the security challenges. Threat profiling allows analysts to understand and organize intelligent information related to threat groups. This paper presents a comparative analysis that was conducted to study the existing threat profiling models. It was found that existing threat models were constructed based on specific objectives, thus each model is limited to only certain components or factors such as assets, threat sources, countermeasures, threat agents, threat outcomes and threat actors. It is suggested that threat profiling can be improved by the combination of components found in each existing threat profiling model/framework. The proposed model can be used by an organization in executing a proactive approach to incident management.
ISSN:1742-6588
1742-6596
DOI:10.1088/1742-6596/892/1/012011