Moustafa Ahmed A, Bello Abubakar, Maurushat Alana
School of Psychology, Western Sydney University, Sydney, NSW, Australia.
The Marcs Institute for Brain, Behaviour and Development, Western Sydney University, Sydney, NSW, Australia.
Front Psychol. 2021 Jun 18;12:561011. doi: 10.3389/fpsyg.2021.561011. eCollection 2021.
Information security has for long time been a field of study in computer science, software engineering, and information communications technology. The term 'information security' has recently been replaced with the more generic term cybersecurity. The goal of this paper is to show that, in addition to computer science studies, behavioural sciences focused on user behaviour can provide key techniques to help increase cyber security and mitigate the impact of attackers' social engineering and cognitive hacking methods (i.e., spreading false information). Accordingly, in this paper, we identify current research on psychological traits and individual differences among computer system users that explain vulnerabilities to cyber security attacks and crimes. Our review shows that computer system users possess different cognitive capabilities which determine their ability to counter information security threats. We identify gaps in the existing research and provide possible psychological methods to help computer system users comply with security policies and thus increase network and information security.
长期以来,信息安全一直是计算机科学、软件工程和信息通信技术领域的研究内容。“信息安全”一词最近已被更通用的“网络安全”一词所取代。本文的目的是表明,除了计算机科学研究之外,专注于用户行为的行为科学可以提供关键技术,以帮助提高网络安全并减轻攻击者的社会工程和认知黑客方法(即传播虚假信息)的影响。因此,在本文中,我们确定了当前关于计算机系统用户心理特征和个体差异的研究,这些研究解释了网络安全攻击和犯罪的脆弱性。我们的综述表明,计算机系统用户具有不同的认知能力,这些能力决定了他们应对信息安全威胁的能力。我们找出了现有研究中的差距,并提供了可能的心理学方法,以帮助计算机系统用户遵守安全政策,从而提高网络和信息安全。