当前位置: X-MOL 学术Int. J. Disaster Risk Reduct. › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
Passive and active training approaches for critical infrastructure protection
International Journal of Disaster Risk Reduction ( IF 4.2 ) Pub Date : 2021-07-21 , DOI: 10.1016/j.ijdrr.2021.102461
Luisa Franchina 1 , Giulia Inzerilli 1 , Enrico Scatto 1 , Alessandro Calabrese 1 , Andrea Lucariello 1 , Giulia Brutti 1 , Priscilla Roscioli 1
Affiliation  

In order to strengthen Critical Infrastructure's protection and resilience, it is central to invest in training and simulations, to spread a security culture and develop the awareness among all personnel involved in the Critical Infrastructure security. Nowadays, attackers represent a major threat due to the combination of both cyber and kinetic operations, targeting human factors vulnerabilities. It is also critical to develop and straighten a “human firewall” inside critical organizations through the enhancement of Security Education, Training and Awareness (SETA) and stresses the need for the development of a security culture inside organizations. In such scenarios, today, the awareness within organizations, both in public and private sector, is achieved through passive and active training techniques. A hybrid approach is proposed as a powerful compromise between the two that can best deliver the desired level of awareness and meet the needs and satisfaction of employees. Adopting a balanced mix of techniques that comprise engagement-based and less interactive methods seems to be the best way to attain security awareness.



中文翻译:

关键基础设施保护的被动和主动培训方法

为了加强关键基础设施的保护和恢复能力,投资于培训和模拟、传播安全文化并提高所有参与关键基础设施安全的人员的意识至关重要。如今,由于网络和动能操作的结合,攻击者代表了一种主要威胁,针对人为因素的漏洞。通过加强安全教育、培训和意识 (SETA) 来在关键组织内部发展和整顿“人类防火墙”也很重要,并强调在组织内部发展安全文化的必要性。在这种情况下,今天,公共和私营部门组织内的意识是通过被动和主动培训技术实现的。混合方法被提议作为两者之间的强大折衷方案,可以最好地提供所需的意识水平并满足员工的需求和满意度。采用包含基于参与和较少交互方法的技术的平衡组合似乎是获得安全意识的最佳方式。

更新日期:2021-07-23
down
wechat
bug