Social Aspects of Information Security.
Evangelos D. Frangopoulos, Mariki M. Eloff, Lucas M. Venter · 2008
Social Engineering (SE) threats have constituted a reality for Information Technology (IT) systems for many years. Yet, even the latest editions of the generally accepted Information Security (IS) standards and best practices directives do not effectively address the Social Engineering aspect of IS defences. SE attacks target the human element of IS by exploiting human relations to the maximum possible extent. The social relations between interacting individuals who are involved in an Information Security Management System (ISMS) structure, combined with the frequently unpredictable fashion that humans act and react to stimuli, provide opportunities that Social Engineers may and do exploit. In the ongoing effort against Social Engineering attacks, if the social elements of IS are ignored, fallacious working assumptions may be made. These inadvertently result in the creation of insufficient controls against identified SE threats. Hence, simply put, Information Security scientists can no longer afford to ignore the nature of the social structures that govern all aspects of human relations, and in particular those that lie within the context of an ISMS. This paper attempts to strengthen the pursued research on SE threat identification and control, by applying sociological principles to IT and ISMSs, thus bringing into the light their nature as social structures. This constitutes part of a larger effort by the authors to systematically identify and subsequently cater for SE threats to IS, in the context of which the social foundations of IS are examined. KEY WORDS