Method of Assessing the Influence of Personnel Competence on Institutional Information Security

- Pilkevych, Ihor (orcid.org/0000-0001-5064-3272), Boychenko, Oleg (orcid.org/0000-0003-3048-4184), Lobanchykova, Nadiia (orcid.org/0000-0003-4010-0308), Vakaliuk, Tetiana (orcid.org/0000-0001-6825-4697) and Semerikov, Serhiy O. (orcid.org/0000-0003-0789-0272) (2021) Method of Assessing the Influence of Personnel Competence on Institutional Information Security Proceedings of the 2nd International Workshop on Intelligent Information Technologies & Systems of Information Security with CEUR-WS Khmelnytskyi, Ukraine, March 24–26, 2021 (2853). pp. 266-275. ISSN 1613-0073

[img] Text
paper33.pdf - Published Version

Download (357kB)

Abstract

Modern types of internal threats and methods of counteracting these threats are analyzed. It is established that increasing the competence of the staff of the institution through training (education) is the most effective method of counteracting internal threats to information. A method for assessing the influence of personnel competence on institutional information security is proposed. This method takes into account violator models and information threat models that are designed for a specific institution. The method proposes to assess the competence of the staff of the institution by three components: the level of knowledge, skills, and character traits (personal qualities). It is proposed to assess the level of knowledge based on the results of test tasks of different levels of complexity. Not only the number of correct answers is taken into account, but also the complexity of test tasks. It is proposed to assess the assessment of the level of skills as the ratio of the number of correctly performed practical tasks to the total number of practical tasks. It is assumed that the number of practical tasks, their complexity is determined for each institution by the direction of activity. It is proposed to use a list of character traits for each position to assess the character traits (personal qualities) that a person must have to effectively perform the tasks assigned to him. This list should be developed in each institution. It is proposed to establish a quantitative assessment of the state of information security, defining it as restoring the amount of probability of occurrence of a threat from the relevant employee to the product of the general threat and employees of the institution. An experiment was conducted, the results of which form a particular institution show different values of the level of information security of the institution for different values of the competence of the staff of the institution. It is shown that with the increase of the level of competence of the staff of the institution the state of information security in the institution increases.

Item Type: Article
Keywords: Assessment of the level of knowledge, competence, information threats, a model of the internal violator, model threats
Subjects: Science and knowledge. Organization. Computer science. Information. Documentation. Librarianship. Institutions. Publications > 00 Prolegomena. Fundamentals of knowledge and culture. Propaedeutics > 004 Computer science and technology. Computing. Data processing > 004.9 ІКТ ( Application-oriented computer-based techniques )
Divisions: Institute for Digitalisation of Education > Department of the Cloud-Вased Systems of ICT in Education
Depositing User: Сергій Олексійович Семеріков
Date Deposited: 11 Oct 2021 04:00
Last Modified: 11 Oct 2021 04:00
URI: https://lib.iitta.gov.ua/id/eprint/726926

Downloads

Downloads per month over past year

Actions (login required)

View Item View Item