
As data breaches in mid-sized to large organizations become more frequent and more public, there is a need to focus less on technological solutions to information security management and more on sociological solutions. In this paper cost saving information security initiatives are identified and a framework is proposed for organizational and behavioral change in technical human resources, to better address information security concerns.
Service-oriented architectures implemented by web services technologies provide standardized protocols for communicating and sharing information across organizational boundaries. The access control of shared services becomes an essential requirement for a secure federation of services. The identity federation provides part of the response by allowing users to authenticate once in an organization and to access the services of others with its authorization information or attributes. However, in a federation, the organizations may have different access control models and authorization attributes with different or even incompatible semantics. Interoperability between the access control models becomes crucial to the federation of services. Existing federated access control solutions are based on the single sign-on with common authorization attributes or the identity mapping that is not scalable in a service-oriented environment. In this paper, we propose a cross-organizational access control method for the federation of services protected by heterogeneous access control models. Our method is based on a new federation architecture that responds to the heterogeneity of authorization attributes via independent attributes introduced at the federation level.
Consent management is a significant function in electronic healthcare. Given the rise of personal data stored on electronic devices, there is a need to ensure that personal data of individuals is protected—in particular, healthcare user information stored on health information systems. In addition to the basic protection of healthcare user information, healthcare users should also be informed how and by whom their personal information may be used. Through the adoption of transparency by the healthcare service provider, healthcare users are placed in a position to control access to their health information and to reduce the risks for reputational and personal harm. This paper presents a conceptual model for consent management in e-healthcare. The application of the model in e-healthcare will ensure that the following four main requirements are satisfied for the healthcare user: informativity, modifiability, controllability and end-to-end security.
Information security awareness (ISA) is a vital component of information security in organizations. The purpose of this research is to descriptively review and classify the current body of knowledge on ISA. A sample of 59 peer-reviewed academic journal articles, which were published over the last decade from 2008 to 2018, were analyzed. Articles were classified using coding techniques from the grounded theory literature-review method. The results show that ISA research is evolving with behavioral research studies still being explored. Quantitative empirical research is the dominant methodology and the top three theories used are general deterrence theory, theory of planned behavior, and protection motivation theory. Future research could focus on qualitative approaches to provide greater depth of ISA understanding.
Information security management is a difficult task in organisations. Owing to skills shortages and the like, there are relatively few managerial staff that possess the required expertise to confidently make security decisions. The purpose of this paper is to present a decision support system that can analyse, and provide insight into, information security behaviour in an organisation, all the while supporting management decision-making for organisational factors. Behavioural threshold analysis is employed by the system to predict eventual information security behaviour for different groupings in an organisation. The decision support system that is presented here, which is the first of its kind, can be helpful in understanding the current state of organisational information security behaviour, and what can be done to improve upon the current state. After intervention measures the system may be used to test whether these measures had the intended positive effect. The system is discussed in terms of the different information areas that are used to allow insight into the security behaviours. A critical reflection provides an analysis of the contributions and limitations of the system.
The introduction of fitness wearables has encouraged users to take control of their health and fitness habits. These wearables are capable of collecting real-time data through the sensors embedded within the devices. The collection of real-time data about the users is a concern, as exactly what data is collected by these wearables is not clear to the users. Security threats and vulnerabilities in the fitness wearable domain continue to increase due to the increasing use of these wearables. This study aims to investigate and analyse security vulnerabilities and threats that affect fitness wearables from a security and privacy perspective. The execution of this study involves two phases of methodology. The first phase employs a systematic literature review and qualitative content analysis to identify the threats and vulnerabilities affecting fitness wearables. The second phase employs the Microsoft STRIDE framework and CIA triad to conduct an analysis of the threats and vulnerabilities. The output of this study indicates that security is still a great concern, as these fitness wearables are exposed to various security threats. Furthermore, these security threats increase due to the many components that are part of the fitness wearable architecture creating multiple entry points for attackers.
Computer Security Incident Response Teams (CSIRTs) provide information security incident response services to communities. The South African Cybersecurity Hub (SACH) acts as a national point of contact for the coordination of cybersecurity incidents in South Africa, but to date has only been successful in assisting with the establishment of a finance sector CSIRT. No mention of a transport or critical infrastructure sector CSIRT, under which an aviation CSIRT can report aviation sector cyber-attacks is made. The aviation community is mandated to sustain safety and security of operations and passengers in Southern Africa. Acknowledging the urgency and importance of protecting civil aviation’s critical infrastructure, information and communication technology systems and data against cyber threats this research identifies that there is a need for a CSIRT framework for the Sub-Saharan aviation community. An aviation CSIRT should implement frameworks, programs and international information security standards, and aviation communities need to share cyber information with the CSIRT. To achieve such a framework, globally established CSIRTs are reviewed. Since the aviation sector is complex to manage, there is a need to establish an integrated CSIRT approach that include stakeholders within the ecosystem. A proposed aviation CSIRT requires the adoption of best practice cyber security incident response standards as a practical solution to manage aviation cyberattacks.
Centralized data architectures are the predominant architectures used by systems today. Decentralized data architectures, making use of data link networks, allow users to store private data in personal online data stores (POD). When fitness data is stored in a POD, the user has full control over the data and may modify fitness data. Medical aid providers that makes use of fitness data for benefit calculations cannot trust fitness data in existing POD architectures. PAUDIT is an architectural model that describes a decentralized data architecture that audits changes to access control lists on POD servers. The audit information allows medical aid providers to verify if users may have changed fitness data. PAUDIT describes an architecture that allows medical aid providers to verify the validity of fitness data.
As data breaches in mid-sized to large organizations become more frequent and more public, there is a need to focus less on technological solutions to information security management and more on sociological solutions. In this paper cost saving information security initiatives are identified and a framework is proposed for organizational and behavioral change in technical human resources, to better address information security concerns.
The protection of people’s privacy is both a legal requirement and a key factor for doing business in many jurisdictions. Organisations thus have a legal obligation to get their privacy compliance in order as a matter of business importance. This applies not only to organisations’ day-to-day business operations, but also to the information technology systems they use, develop or deploy. However, privacy compliance, like any other legal compliance requirements, is often seen as an extra burden that is both unnecessary and costly. Such a view of compliance can result in negative consequences and lost opportunities for organisations. This paper seeks to position data privacy compliance as a value proposition for organisations by focusing on the benefits that can be derived from data privacy compliance as it applies to a particular subset of information technology systems, namely cyber-physical systems and Internet of Things technologies. A baseline list of data privacy compliance benefits, contextualised for CPSs and IoT with the South African legal landscape is proposed.
The purpose of this paper is to identify the major institutional trust mechanisms that facilitate the adoption of cloud services among South African SMEs. By drawing from Giddens’ (1990) institutional trust theory and the existing IT trust literature, we developed a conceptual model to improve our understanding of the role of institutional trust between SMEs and cloud service providers. The model was also deployed as a sensitizing framework to deepen our understanding of how institutional trust factors influence SME cloud service adoption decisions. A qualitative field study based on 12 semi-structured interviews of SMEs and cloud service providers in South Africa suggests that the insights gleaned from concepts, such as design faults and operator failure, can be translated into useful policy guidelines for cloud service providers, state institutions and regulatory bodies that are working to improve the trustworthiness of the cloud ecosystem. Despite the belief held by experts that there is a need to strengthen institutional mechanisms in the cloud ecosystem, the relative advantage of cloud over alternative technology remains the primary motivational factor of SME adoption. The SMEs in this study were unaware of the risks involved in cloud adoption and are content to mimic the behavior of their peers when adopting cloud services. Other social actors in society will have to play a prominent role in evaluating and strengthening institutional trust in the cloud ecosystem.
Information system security threats perpetuates organisations in spite of enormous investments in security measures. The academic literature and the media reflect the huge financial loss and reputational harm to organisations due to computer related security breaches. Although technical safeguards are indispensable, the academic literature highlights the ‘insider threat’. Organisational employees pose a significant threat, considering, they already have access to the organizations’ information systems. It’s a matter of how they use/abuse it. This article explores the theoretical foundation in the domain of information systems security policy violations. The academic databases are queried for key theories in computer compliance/non-compliance. These theories are examined for theoretical development. A problem area is identified and subsequently, a theoretical model is proposed in an attempt to explain: Why employees violate information systems security policies?
The purpose of this paper is to focus on the security aspects of digital transformation through Unified Communication and Collaboration (UC C) technologies impacting productivity and innovation within a global automotive enterprise. The rationale for the study came from a desire to address the challenge of integrating the complex technology landscape of the Internet of Things in the daily lives of people. This study explored the impact of digitization transformation on people in the context of the automotive industry. A framework for digital transformation via UC C technologies was designed at a large automotive enterprise. Research leveraged qualitative and quantitative methods, following the implementation of the framework and digital transformation. Observational data combined with data from quantitative enterprise metrics to support analysis. Critical realist interpretation of results suggested that digitally transformed UC C technologies are changing employees’ work practices. The study concludes that digital transformation via UC C technologies impact productivity and innovation within a global automotive enterprise.
Vi lever i en apokalyptisk tid. Apokalyptisk argumentation till stor del outforskad. Artikeln presenterar en analysmodell i tre steg: upplevd ondska, tidens tecken och tillforlitlig auktoritet, inspirerad av Stephen O'Leary. Artikeln innehaller tva analysexempel: USA:s forre president Donald Trump och den Islamiska staten. Bada bygger sin argumentation pa en apokalyptisk varldsbild.
Despite the emergence of numerous authentication methods, passwords have remained the dominant authentication mechanism for e-commerce websites. However, password authentications if often widely criticized, especially due to the ease with which it can be compromised by end-users as they often have poor password security behaviors. Nevertheless, a plethora of evidence suggests that the blame should not only be placed on the users as many engage in poor password security practices because they lack sufficient guidance and support on how to maintain good password security behaviors. Indeed, many researchers over the years have shown that user password security behaviors can be significantly enhanced by provided guidance and support on how they can create and maintain strong passwords. Yet, it remains uncertain how well e-commerce website providers have learned these essential lessons. As such, this study is aimed at evaluating the password practices of e-commerce websites in South Africa (SA). After evaluating 37 leading e-commerce websites in the country, it was observed that the majority (92%) of the websites had poor password practices with over 81% offering no guidance for users to enhance their password behaviors. This problem is certainly worse than it should be in this day and age. Consequently, there is an urgent need for e-commerce service providers in SA to improve their password security practices as this is vital for enhancing the password behaviors of their website’s users.
Ever improving technology allows smartphones to become an integral part of people's lives. The reliance on and ubiquitous use of smartphones render these devices rich sources of data. This data becomes increasingly important when smartphones are linked to criminal or corporate investigations. To erase data and mislead digital forensic investigations, end-users can manipulate the data and change recorded events. This paper investigates the effects of manipulating smartphone data on both the Google Android and Apple iOS platforms. The deployed steps leads to the formulation of a generic process for smartphone data manipulation. To assist digital forensic professionals with the detection of such manipulated smartphone data, this paper introduces an evaluation framework for smartphone data. The framework uses key traces left behind as a result of the manipulation of smartphone data to construct techniques to detect the changed data. The outcome of this research study successfully demonstrates the manipulation of smartphone data and presents preliminary evidence that the suggested framework can assist with the detection of manipulated smartphone data.
Organizations worldwide are revisiting the design of their password policies. This is partly motivated by the security and usability limitations of user-generated passwords. While research on password policies has been ongoing, this has taken place in the Global North. Accordingly, little is known about the strengths and weaknesses of password policies deployed in the Global South, especially Africa. As such, this study researched password policies deployed on South African websites. Password policies of thirty frequently visited websites belonging to South African organizations were analyzed. Our observations show diverse password requirements. Even though the desire for strong passwords is the dominant motivator of complex password policies, South African organizations often adopt obsolete measures for attaining password security. The ten most common passwords in the literature were considered acceptable on most sites. In addition, some sites did not explicitly display password requirements and only a few sites adopted measures for providing real-time feedback and effective guidance during password generation.
Although small and medium-sized enterprises (SMEs) are encouraged to seek new business opportunities by adopting and utilising cloud-based services, their understanding of threats, vulnerabilities and risk evaluation in the cloud environment, which is crucial in the success of cloud-based business intelligence (BI) adoption, is hardly known. The purpose of this study was to investigate SMEs’ understanding of security evaluation of cloud-based BI and associated challenges. A cross-sectional survey was conducted among 109 SME owners/managers from selected South African provinces in which data was collected by means of an electronic and postal questionnaire. The study found that SME owners/managers were aware of conventional security challenges in the cloud-based services including BIs, had a basic understanding of security evaluation in general, understood the need to evaluate cloud-based BIs in terms of physically checking for vulnerabilities and data security and were not proficient in performing security evaluations of cloud-based BIs and relied on experts. SMEs face predicaments in evaluating cloud-based BI due to a lack of appropriate tools they can use. The study concluded that SME owners/managers have a basic understanding of security evaluation and challenges it poses.
Face recognition. A promise made to the modern technologists as the ultimate access control or surveillance technology. However, it is still vulnerable to inexpensive spoofing attacks, which pose a threat to security. Basic face spoofing attacks that use photographs and video are still not addressed appropriately, especially in real-time applications, thereby making security in these environments a difficult task to achieve. Although methods have improved over the last decade, a robust solution that can accommodate changing environments is still out of reach. Face spoofing attacks introduce an object into the scene, which presents curvilinear singularities that are not necessarily portrayed in the same way in different lighting conditions. We present a solution that addresses this problem by using a discrete shearlet transform as an alternative descriptor that can differentiate between a real and a fake face without user-cooperation. We have found the approach can successfully detect blurred edges, texture changes and other noise found in various face spoof attacks. Our benchmarks on the publicly available CASIA-FASD, MSU-MFSD, and OULU-NPU data sets, show that our approach portrays good results and improves on the most popular methods found in the field on modest computer hardware, but requires further improvement to beat the current state of the art. The approach also achieves real-time face spoof discrimination, which makes it a practical solution in real-time applications and a viable augmentation to current face recognition methods.
This paper examines the way in which blockchain technology can be used to improve the integrity of the chain of evidence in digital forensics. A particular scalable method of verifying point-in-time existence of a piece of digital evidence, using the OpenTimestamps (OTS) service, is described, and tests are carried out to independently validate the claims made by the service. The results demonstrate that the OTS service is highly reliable, but not suitable for time-sensitive digital timestamping.