Loading...
1 results
Search Results
Now showing 1 - 1 of 1
- Information security threat assessment using social engineering in the organizational context: literature reviewPublication . Lopes, António; Reis, Leonilde; São Mamede, Henrique; Santos, ArnaldoCurrently, due to the value and diversity of data that organizations use and produce in their activity, it is extremely important to protect this asset. Security flaws can arise due to several factors and whenever it is difficult to gain access to the desired information, because of technological barriers. In this case, attacks are redirected to the exploitation of human beings vulnerabilities, through various techniques. The objective of this work focuses on literature review, studying the underlying theme of Social Engineering, as it uses human trust, convincing someone of something fake, using various interactions and different vectors to gain access to private information. The research work will be supported by Design Science Research, due to the possibility of construction, evaluation, and subsequent validation of the artifact. The contribute of a framework proposal for preventing social engineering attacks in organizations and provide the best recommendations, guiding, and supporting the stakeholders in the selection and definition of controls that guarantee the security of organizational information and avoid possible attacks by Social Engineering. It is expected that the practical ef-fects of the future work will result in a reduction in the number of attacks using Social Engineering, greater individual and collective preparation to deal with this problem and, over time, the incentive to continued expansion of the adoption of these artifacts at the organizational level.