An information security ontology incorporating human-behavioural implications
Simon E. Parkin, Aad van Moorsel, Robert S. Coles · 2009
Security managers often regard human behaviour as a security liability, but they should accommodate it within their organisation's information security management procedures. To further the comprehension of human-behavioural factors we develop an information security ontology. This ontology is intended for organisations that aim to maintain compliance with external standards (in this case ISO27002) while considering the security behaviours of individuals within the organisation.