William-Rogelio Marchand-Niño

dblp:309/7408 · DBLP profile ↗
← Back
2ranked-venue papers
2as first author
2since 2021 · last 2023
0000-0003-2650-4226ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2023 Pretexting and the Information Security Culture. Case of a University of the Peruvian Amazon
abstract
Information security is to protect information from unauthorized access that causes irreparable damage to people and organizations. Security measures must cover both the technical and organizational aspects. It is precisely the organizational aspect related to the security culture that must be strengthened with greater efforts, because social engineering attacks against users continue to be a path of success for cybercriminals. In this investigation, pretexting was carried out, a social engineering technique that was applied to a university of peruvian amazon, whose organizational culture is like others in the interior of the country. The objective was to evaluate the behavior of users in terms of awareness and appropriation against social engineering techniques such as pretexting. The applied methodology included the definition of excuse, preparation of instruments, selection of target persons, chronological programming of execution, application of the exercise, analysis, and data processing. The excuse was related to the collection of data from the computer equipment for a diagnosis of the computer park as part of an investigation to formulate technological optimization solutions. Some results obtained were: 15% of the people reached requested some type of authorization, 70% showed no interest in supervising the data that was collected from the computer, and 40% of users stored passwords in the browser without additional protection. This reflects the low to medium levels of awareness and ownership for the security culture in this case.
William-Rogelio Marchand-Niño, Yarid-Vanessa Vargas-Malca
CLEI1
2021 Information Security Culture Model. A Case Study
abstract
This research covers the problem related to user behavior and its relationship with the protection of computer assets in terms of confidentiality, integrity, and availability. The main objective was to evaluate the relationship between the dimensions of awareness, compliance and appropriation of the information security culture and the asset protection variable, the ISCA diagnostic instrument was applied, and social engineering techniques were incorporated for this process. The results show the levels of awareness, compliance and appropriation of the university that was considered as a case study, these oscillate between the second and third level of four levels. Similarly, the performance regarding asset protection ranges from low to medium. It was concluded that there is a significant relationship between the variables of the investigation, verifying that of the total types of incidents registered in the study case, approximately 69% are associated with human behavior. As a contribution, an information security culture model was formulated whose main characteristic is a complementary diagnostic process between surveys and social engineering techniques, the model also includes the information security management system, risk management and security incident handling as part of the information security culture ecosystem in an enterprise.
William-Rogelio Marchand-Niño, Hector Huamán Samaniego
CLEI1