Loading...
2 results
Search Results
Now showing 1 - 2 of 2
- Towards a comprehensive framework for the multidisciplinary evaluation of organizational maturity on business continuity program management: a systematic literature reviewPublication . Russo, Nelson; Reis, Leonilde; Silveira, Clara; São Mamede, HenriqueOrganizational dependency on Information and Communication Technology (ICT) drives the preparedness challenge to cope with business process disruptions. Business Continuity Management (BCM) encompasses effective planning to enable business functions to resume to an acceptable state of operation within a defined timeframe. This paper presents a systematic literature review that communicates the strategic guidelines to streamline the organizational processes in the BCM program, culminating in the Business Continuity Plan design, according to the organization’s maturity. The systematic literature review methodology follows the Evidence- Based Software Engineering protocol assisted by the Parsifal tool, using the EbscoHost, ScienceDirect, and Scopus databases, ranging from 2000 to February 2021. International Standards and Frameworks guide the BCM program implementation, however, there is a gap in communicating metrics and what needs to be measured in the BCM program. The major paper result is the confirmation of the identified gap, through the analysis of the studies that, according to the BCM components, report strategic guidelines to streamline the BCM program. The analysis quantifies and discusses the contribution of the studies on each BCM component to design a framework supported by metrics, that allows assessing the organization’s preparedness in each BCM component, focusing on Information Systems and ICT strategies.
- Information security threat assessment using social engineering in the organizational context: literature reviewPublication . Lopes, António; Reis, Leonilde; São Mamede, Henrique; Santos, ArnaldoCurrently, due to the value and diversity of data that organizations use and produce in their activity, it is extremely important to protect this asset. Security flaws can arise due to several factors and whenever it is difficult to gain access to the desired information, because of technological barriers. In this case, attacks are redirected to the exploitation of human beings vulnerabilities, through various techniques. The objective of this work focuses on literature review, studying the underlying theme of Social Engineering, as it uses human trust, convincing someone of something fake, using various interactions and different vectors to gain access to private information. The research work will be supported by Design Science Research, due to the possibility of construction, evaluation, and subsequent validation of the artifact. The contribute of a framework proposal for preventing social engineering attacks in organizations and provide the best recommendations, guiding, and supporting the stakeholders in the selection and definition of controls that guarantee the security of organizational information and avoid possible attacks by Social Engineering. It is expected that the practical ef-fects of the future work will result in a reduction in the number of attacks using Social Engineering, greater individual and collective preparation to deal with this problem and, over time, the incentive to continued expansion of the adoption of these artifacts at the organizational level.