2 resultados para Insider

em Universidade do Minho


Relevância:

20.00% 20.00%

Publicador:

Resumo:

Security risk management is by definition, a subjective and complex exercise and it takes time to perform properly. Human resources are fundamental assets for any organization, and as any other asset, they have inherent vulnerabilities that need to be handled, i.e. managed and assessed. However, the nature that characterize the human behavior and the organizational environment where they develop their work turn these task extremely difficult, hard to accomplish and prone to errors. Assuming security as a cost, organizations are usually focused on the efficiency of the security mechanisms implemented that enable them to protect against external attacks, disregarding the insider risks, which are much more difficult to assess. All these demands an interdisciplinary approach in order to combine technical solutions with psychology approaches in order to understand the organizational staff and detect any changes in their behaviors and characteristics. This paper intends to discuss some methodological challenges to evaluate the insider threats and its impacts, and integrate them in a security risk framework, that was defined according to the security standard ISO/IEC_JTC1, to support the security risk management process.

Relevância:

10.00% 10.00%

Publicador:

Resumo:

Universities are increasingly institutionalizing activities related to technology transfer and one of the main institutional mechanisms that has emerged is the “technology transfer unit” (TTU). Many of them are focusing their activities on the management of the university intellectual property. Studies have investigated factors that seem to affect their performance, but few have looked in detail at internal procedures and techniques that are used in their processes related to technology evaluation and licensing. The aim of this paper is to provide a comprehensive overview of some of the several steps that comprises the processes regarding technology evaluation and licensing, providing an analysis of the critical issues that affect each step of the process. A review of the literature was made, complemented with interviews to seven university TTUs, which was used as a check and a complement to the literature review and as way of perceiving from an insider perspective, the problems and issues that this paper wants to emphasize and to state clearly.