Analyzing Enterprise Security Using Social Networks and Structuration Theory
Richard A. Huebner, Margaret Britt · The Journal of Applied Management and Entrepreneurship · 2006
Executive Summary The information security literature contains references to technical mechanisms for securing enterprises. Fewer papers focus on the behavioral and social aspects of security. Practitioners need to address both technical and behavioral issues in their security programs. This paper develops new model to help researchers and practitioners analyze the behavioral aspects of security. We use emotional intelligence, structuration theory, and social network analysis to analyze social and behavioral issues related to security. Our approach helps information security practitioners identify behaviors that pose risk to enterprise security. Introduction Information security is primarily concerned with the confidentiality, availability, and integrity of data. Technical mechanisms, such as firewalls, honeypots, and intrusion detection systems (IDS), are used to create virtual wall between the and the Internet. While the technical mechanisms give some level of protection to the organization, one must also recognize that employee behavior affects security. Certain employee behaviors can be threat to enterprise security. Models address these types of security-related problems. The models often describe framework to work within, but do not dictate exact technical security mechanisms an ought to implement. Therefore, an enterprise's security needs usually dictate the technical mechanisms that should be implemented. This paper focuses on information security at the firm level and develops the idea that security should be examined through socio-behavioral lens in addition to technical viewpoints. Much of the existing literature in information security tends to focus on technical mechanisms while leaving the behavioral and social aspects aside. We developed this socio-behavioral model of security to supplement existing models. We suggest that our proposed model be used in conjunction with other models. It investigates the way security affects human behavior and organizational structures and vice versa. Security Swanson and Guttman (1996) put forth the idea that social and behavioral issues are no less important than technical issues. Many organizations neglect the consideration of social and behavioral issues in relation to their security programs. Swanson and Guttman's primary contribution is detailed examination of generally accepted security principles. These principles and practices include policy creation and management, program management, risk management and risk mitigation, life cycle planning, personnel and user issues, disaster and contingency planning, incident handling, and awareness and training. Personnel and user issues are an important aspect of complete security program within an organization. The authors make it clear that many important issues in computer security involve users, designers, implementers, and (Swanson & Guttman, 1996, p. 27). Organizations need to do better job addressing the non-technical aspects of security. A major part of security is managing risk. Stoneburner, Goguen, and Feringa (2002) state that risk management enables an to accomplish its mission through three primary actions. First, increase the security of the IT systems that store, process, or transmit information. second, allow managers to make well-informed decisions to justify IT expenditures. Third, assist management by authorizing IT systems based on supporting documentation resulting from the performance of risk management (Stoneburger, et al., 2002). Three primary risk management processes include risk assessment, risk mitigation, and evaluation and assessment. What is risk? Stoneburner (2002) defines risk as a function of the likelihood of given threat-source's exercising particular potential vulnerability and the resulting impact of that adverse event on the organization (Stoneburner, 2002, p. …