| Literature DB >> 35062504 |
Alok Mishra1,2, Yehia Ibrahim Alzoubi3, Asif Qumer Gill4, Memoona Javeria Anwar4.
Abstract
Cybersecurity is a critical issue that must be prioritized not just by enterprises of all kinds, but also by national security. To safeguard an organization's cyberenvironments, information, and communication technologies, many enterprises are investing substantially in cybersecurity these days. One part of the cyberdefense mechanism is building an enterprises' security policies library, for consistent implementation of security controls. Significant and common cybersecurity policies of various enterprises are compared and explored in this study to provide robust and comprehensive cybersecurity knowledge that can be used in various enterprises. Several significant common security policies were identified and discussed in this comprehensive study. This study identified 10 common cybersecurity policy aspects in five enterprises: healthcare, finance, education, aviation, and e-commerce. We aimed to build a strong infrastructure in each business, and investigate the security laws and policies that apply to all businesses in each sector. Furthermore, the findings of this study reveal that the importance of cybersecurity requirements differ across multiple organizations. The choice and applicability of cybersecurity policies are determined by the type of information under control and the security requirements of organizations in relation to these policies.Entities:
Keywords: cybersecurity (CS); cybersecurity polices; cyberspace; enterprise(s); information and communication technology (ICT)
Mesh:
Year: 2022 PMID: 35062504 PMCID: PMC8778887 DOI: 10.3390/s22020538
Source DB: PubMed Journal: Sensors (Basel) ISSN: 1424-8220 Impact factor: 3.576
Figure 1Cybersecurity policies taxonomy.
Surveyed papers significance and focus.
| Reference | Significance | Security Policy |
|---|---|---|
| [ | An overview of the issues and necessity for critical infrastructure protection, as well as the worldwide hazards that are associated with it | Privacy policy |
| [ | Outline the current situation of privacy law in the USA and how it differs from other nations in terms of substantive safeguards | |
| [ | Examining how the legislative systems in Europe and the USA aid in the protection of sensitive customer data on the Cloud | |
| [ | Privacy and data-protection regulations | |
| [ | End-to-end privacy and security control for collaborative access to healthcare | |
| [ | Coordination between IT, business, and information security initiatives is addressed by an integrated framework | |
| [ | The European Union (EU) General Data Privacy Regulation (GDPR) to address difficulties linked to personal data protection and to unify data protection across the EU | |
| [ | Family Educational Rights and Private Act (FERPA) in the USA to protect students’ personal privacy while also making their educational data available to them | |
| [ | Balance student’s privacy, anonymity, and big data in the social sciences | |
| [ | Personalization of web pages for online users | |
| [ | Law enforcement and trusted traveler programs are blurring the lines between privacy and security | |
| [ | A conceptual model that blends the Unified Theory of Acceptance and Use of Technology (UTAUT) with risk perception to analyze online banking behavior intention and utilization | Website policy |
| [ | Multidomain research of phishing-website detection technologies to calibrate the trust of automated security IT artifacts | |
| [ | A model to enhance social media access control systems | |
| [ | Explore the methods of security used by websites—how should we safeguard our data, and what is the best course of action? | |
| [ | Delivers up-to-date research on customer sentiments, beliefs, thoughts, intentions, and attitudes toward effective customer interaction management | |
| [ | A theoretical framework for cybersecurity management in Cloud computing based on a semantic review of the literature | Cloud policy |
| [ | A model for dealing with the issues of data-intensive applications on mobile Cloud platforms | |
| [ | Addresses data security problems and solutions in Cloud computing paradigms including delivery of services and deployment strategies | |
| [ | A study model that merged aspects of information systems security policy | |
| [ | Discuss why banks need to implement additional security measures in addition to the protection supplied by the cloud vendors | |
| [ | Discussion of the use of cloud computing in different aviation and aerospace businesses, as well as the growing technology concerns | |
| [ | Using a digital signature with the RSA encryption method to improve the data security of cloud computing | |
| [ | A model to integrate Cloud computing and e-commerce as a service | |
| [ | Examine the privacy and security concerns created by the usage of the Cloud in e-health | |
| [ | Invention applications and the USA patent and trademark office’s success | Email policy |
| [ | An overview of the law at USA schools and security challenges | |
| [ | Using email user insights to guide organizational email management policies | |
| [ | Evaluation of employee sensitivity to phishing attacks in US healthcare facilities | |
| [ | Discussion of the best standard for email encryption for Health Information Technology for Economic and Clinical Health (HITECH) Act compliance to secure Protected Health Information (PHI) | |
| [ | Study on the role of Russian “patriotic hackers” in the cyberattacks on Estonia and Georgia in 2007 and 2008, and how the expertise of surviving this attack aided | |
| [ | A new approach for detecting fake customer reviews | |
| [ | A machine-learning-based approach for detecting spam with high accuracy | |
| [ | Comparison between the United Kingdom and France in terms of safeguarding key infrastructure from cyberattacks | Physical policy |
| [ | An explanation of the distinctions between information security and cybersecurity | |
| [ | Guidelines for information security standards, procedures, and policies | |
| [ | Examining information security policies and objectives and offering insights on them through a rigorous theoretical perspective | |
| [ | Explanation of physical security and information security, and why treating these two distinct forms of security in a unified manner is vital in today’s shifting security scenario | |
| [ | A theoretical model that studies the link between security, perceived risks, and privacy, and how they relate to customers’ confidence in e-commerce | |
| [ | Providing baseline information on the Data Protection Officer (DPO) in order to ensure data security and compliance | |
| [ | A survey on privacy protection and data security for Cloud storage | Network policy |
| [ | An overview of cybersecurity and networks that emphasizes their linkages and the complexity of current network design challenges | |
| [ | An examination of the smart grid’s IoT-based security issues and potential remedies | |
| [ | A review of security vulnerabilities in wireless medical sensor network-enabled healthcare applications | |
| [ | Review of the Directive 2011/24/EU on patients’ rights in cross-border healthcare | |
| [ | Discussion of the concept and development of The Interface to Network Security Functions (I2NSF) architecture, providing ways to improve its efficiency through integration with SDN | |
| [ | Network security concepts and guidelines | |
| [ | Review of risks and remedies in e-learning systems | |
| [ | Outlines the primary variables that underlie the United States’ attempts to improve their cybercapacity | |
| [ | Exploring an innovative approach to privacy protection and providing a persuasive collection of prospective legislative suggestions and practical answers | |
| [ | A comprehensive framework that covers all areas of online learning design, creation, and planning | Information policy |
| [ | A bibliometric investigation of the structure, quality, and quantity of e-commerce usage in emerging economies’ small- and medium-sized businesses | |
| [ | Analysis of security flaws in the Automatic Dependent Surveillance-Broadcast (ADS-B) system and suggestions to improve security | |
| [ | An overview of current and future challenges facing behavioral information security | |
| [ | An overview of information security policy violations by employees in corporate contexts | |
| [ | A model, using a Chaotic Map-Based Three-Factor Authenticated Key Agreement Scheme to Secure Telecare Medical Information Systems | |
| [ | An overview of the electronic banking service, stressing several security concerns and proposing potential solutions | |
| [ | An overview of remote working software professionals’ perceptions on the Information Security Policy (ISP) and the factors that should be considered in order to keep remote employees in the software sector productive | |
| [ | Discussion about Saudi Arabia’s e-government vulnerabilities and the necessity for a defined information security system | |
| [ | Evaluation of the Cloud security by defining specific security needs and solutions that overcome possible threats | Access control policy |
| [ | A framework that enables academics to improve their efforts in the field of insider attacks | |
| [ | A model to enhance privacy and access control in electronic health-record systems | |
| [ | A strategy for obtaining safe banking services on multimedia large data in Cloud computing | |
| [ | An overview of online banking communication and authentication security issues | |
| [ | Elucidate the main security concerns that must be addressed while creating while using an e-learning system | |
| [ | An overview of essential challenges of big data, such as technological difficulties, a lack of expertise, and epistemological and ontological disparities | Data-retention policy |
| [ | An overview of privacy rights and regulation of personal data retention and erasure in European Union (EU) | |
| [ | A book of the illegal and legal considerations of information security | |
| [ | Two models for standardizing audit query meaning | |
| [ | A model of HIPAA compliance regulations for clinician texting | |
| [ | A policy framework to create an environment that allows for ethical data collection and use, and to address concerns of susceptibility | |
| [ | An overview of European security laws in European passenger name recording system | |
| [ | Discussion of the European proposal to share the personal information of all passengers | |
| [ | An assessment of the transnational problems faced by government monitoring and business interference on the right to privacy | |
| [ | A book on information technology crimes and regulations | Data-protection policy |
| [ | An overview of the privacy problems of wearable personal health-monitoring equipment | |
| [ | A book on e-commerce, IT, and data protection in Europe | |
| [ | E-health, privacy, IoT, design, and corporate compliance framework | |
| [ | An examination of the primary data-sharing tools utilized by police agencies and intelligence agencies in the EU and the US was conducted between 2001 to 2015 | |
| [ | A review of the privacy of personal data in the Malaysian setting | |
| [ | A review of the evolution of information security policy | Website and information policies |
| [ | Evaluation of Cloud security concerns and designing preventions or remedies, depending on the source or cause of a security issue | Cloud and data-protection policies |
| [ | A book on the development of information security in healthcare | Privacy, network, information, access control, data protection, and data-protection policies |
| [ | A review of cybersecurity metrics and their applications in e-learning systems | Information and access control policies |
| [ | An investigation into the ethical concerns surrounding the aviation industry in Indonesia | Physical and access control policies |
| [ | Evaluation of the access controls applied on IoT, including the adoption of access controls and the challenges of access control techniques | Network and access control policies |
| [ | An assessment of Cloud computing security and privacy, as well as a proposal for a framework of possible solutions | |
| [ | An overview of the European Union’s General Data Protection Regulation (GDPR) | Privacy, website, and data-protection policies |
| [ | Evaluation of security design methods and their qualities, we used a hybrid technique called Fuzzy AHP-TOPSIS (Analytic Hierarchy Process-Technique for Order Preference by Similarity Ideal Solution) | Website and network policies |
| [ | Examining the background and future possibilities of body scanners vs. data protection and privacy via the lenses of challenges, legal tools, and potential remedies | Privacy and data-protection policies |
| [ | A review of how small- and medium-sized businesses manage cybersecurity risks | Website, email, access control, data-retention policies |
| [ | A review of e-commerce security challenges and solutions | Cloud, network, information, access control, physical, and data-retention policies |
| [ | A book of CompTIA Advanced Security Practitioner (CASP) certificate guidelines | Cloud and email policies |
| [ | Analysis of e-commerce and mobile commerce (M-Commerce) security issues and solutions | Email and physical policies |
| [ | A book on public aviation law that covers international safety requirements, safety rules, and security regulations, among other aviation topics | Physical and information policies |
Comparison matrix of common CS aspects for different enterprises (Red = Very High (VH), Green = High (H), Blue = Average (AVG), Yellow = Low (L)).
| Common Attribute | Healthcare | Finance | Education | Aviation | E-Commerce |
|---|---|---|---|---|---|
| Privacy policy | |||||
| Website policy | |||||
| Cloud computing policy | |||||
| Email policy | |||||
| Physical policy | |||||
| Network policy | |||||
| Information policy | |||||
| Access control policy | |||||
| Retention policy | |||||
| Data protection policy |
Privacy policy among different enterprises.
| Sector | Privacy Policy |
|---|---|
| Healthcare |
Guidelines to secure patient information from unauthorized collection, disclosure, processing, or transmission. Comply with HIPAA Act. |
| Finance |
Guidelines to protect customer’s information and use or process them in legal ways. Prevent financial information from being disclosed without the approval or knowledge of clients. Comply with GLB Act. |
| Education |
Guidelines to protect sensitive data of the student such as health information, grades, disabilities, psychiatric problems, and personal and academic conduct from being disclosed without the students’ agreement. Comply with FERPA laws. |
| Aviation |
Guidelines to protect passenger’s data that show in body-scanner devices in airports from disclosure without his/her knowledge. |
| E-commerce |
Customers’ financial information, such as credit card information, is protected from disclosure, use, and processing without their consent or knowledge. Comply with Fair Credit Reporting Act. |
Website security policy among different enterprises.
| Sector | Website Security Policy |
|---|---|
| Healthcare |
Guidelines to prevent any cross-site scripting and clickjacking. |
| Finance |
Define secure web applications and software to design websites of financial institutions to prevent code-injection attacks. |
| Education |
Define secure web applications and software of academic websites and faculty and student sites to prevent code injection. |
| Aviation |
Define the security of web applications and software of airline websites to prevent code-injection attacks and malicious content. |
| E-commerce |
Define the security of web applications and software of e-commerce websites to protect against code injection. |
Cloud computing security policy among different enterprises.
| Sector | Cloud Computing Security Policy |
|---|---|
| Healthcare |
Authentication methods, firewall devices, and other security measures are used to safeguard Cloud computing equipment to allow a secure connection between patients and servers providers in the health Cloud. |
| Finance |
Financial firm Cloud protection guidelines to offer secure services between clients and financial organizations, utilizing all available security measures to safeguard data, applications, and transactions. |
| Education |
Guidelines to safeguard data, applications, transactions, data server providers, academic programs, and secure connections between students and universities or educational institutions. |
| Aviation |
Using all security measures to safeguard data, applications, transactions, reservation applications, and offer secure connections between airports and clients. |
| E-commerce |
Authentication methods, firewalls, IDs, and intrusion-prevention systems are used to safeguard data, services, and applications to provide secure commercial services and secure financial transactions. Using ID as an electronic identity and signature service over the Internet. |
Email security policy among different enterprises.
| Sector | Email Security Policy |
|---|---|
| Healthcare |
Guidelines to ensure safe contact between patients and medical institutions by advising on how to use emails properly, such as avoiding dangerous attachments and utilizing antispam software, or avoiding opening executable programs. |
| Finance |
When consumers and financial businesses communicate through email, guidelines to offer secure communication techniques through the correct usage of emails and digital signatures are provided. |
| Education |
Guidelines for utilizing emails properly to ensure safe contact between students and institutions, such as avoiding phishing messages, questionable links, and attachments from anonymous addresses, and employing spam filters. |
| Aviation |
Guidelines for providing safe communication for passengers and airline reservation services, as well as the use of software filters to prevent spam emails and dangerous files. |
| E-commerce |
Guidelines for providing safe communication for passengers and airline reservation services, as well as the use of software filters to prevent spam emails and dangerous files. |
Physical security policy among different enterprises.
| Sector | Physical Security Policy |
|---|---|
| Healthcare |
Guidelines to protect all physical assets of health sectors such as buildings of hospitals, medical devices, and network equipment by using physical and digital locks. |
| Finance |
Guidelines to protect physical assets, ATMs, physical buildings, or saving rooms from being destroyed or invaded by using physical and digital locks. |
| Education |
Guidelines to protect academic buildings and universities’ lab equipment and classrooms, learning and teaching materials of educational institutions by using physical and digital locks. |
| Aviation |
Guidelines to protect physical assets of the aviation sector such as airport traffic control towers and surveillance devices by using physical and digital locks. |
| E-commerce |
Guidelines to protect IT resources of e-commerce and online business by using physical and digital locks. |
Network security policy among different enterprises.
| Sector | Network Security Policy |
|---|---|
| Healthcare |
Using several security layers such as firewalls, IDS, and IPS, guidelines to safeguard computer and network devices, traffic networks, and enable secure contact between patients’ end-points and physicians or nurses. |
| Finance |
Guidelines for securing computers and network devices in financial organizations by employing several security layers to enable secure transmission between two PCs. |
| Education |
Multiple security layers are used to safeguard computers and network devices at educational institutions, allowing for secure connections between PCs. |
| Aviation |
Guidelines to protect computers and network devices to provide secure communication between PCs in the aviation industry by many levels of security. |
| E-commerce |
Multi-layer security guidelines to safeguard computer network devices and allow a secure connection between PCs in commercial services. |
Information security policy among different enterprises.
| Sector | Information Security Policy |
|---|---|
| Healthcare |
Guidelines to safeguard all sorts of data, including medical knowledge, statistics, and research data, as well as patient visits. |
| Finance |
Banks and financial organizations should follow these guidelines to secure all of their information and information systems. |
| Education |
Guidelines to safeguard information handled by universities and IT systems, as well as all other types of information such as academic data and scientific research, as well as the systems that process these data. |
| Aviation |
Guidelines for utilizing detecting devices and monitors to secure all airports’ IT and aviation systems. |
| E-commerce |
To earn consumer trust, guidelines to protect all uses of technology and information systems are needed to deliver secure commercial services. |
Access control policy among different enterprises.
| Sector | Access Control Policy |
|---|---|
| Healthcare |
To protect illegal access to patient data and health systems, as well as medical applications, mechanisms are in place. Comply with HIPAA regulations. |
| Finance |
Mechanisms to create strong authentication to control access to financial services to protect accounts and confidentiality of customers’ data. |
| Education |
Mechanisms to manage student or faculty access to university educational websites, regulate student access to their academic sites, and prevent illegal entry. |
| Aviation |
Mechanisms for preventing illegal access to aviation services or airport areas by managing access control and providing authentication. |
| E-commerce |
Access control mechanisms, such as strong passwords, are used to access business websites and conduct financial transactions. |
Data-retention policy among different enterprises.
| Sector | Data-Retention Policy |
|---|---|
| Healthcare |
Rules to govern the secure preservation and destruction of patient data once medical treatments are completed; specify the time limits for which personal data of patients may be saved. |
| Finance |
Rules to ensure secure preservation of customer data, yearly reports, and payment records by encrypting data and deleting client data for old clients when they are no longer needed. Comply with Sarbanes–Oxley Act. |
| Education |
Rules for retaining information on students and alumni in a timely and secure manner, as well as the secure disposal of data relating to former pupils in order to ensure long-term security. |
| Aviation |
Rules for the secure preservation of passenger name records by encryption and anonymized archiving of any old passenger data, as well as for avoiding the storage of passenger scanner pictures. |
| E-commerce |
Rules to ensure secure retention of clients’ data, restrict the keeping of financial information such as credit card numbers and credit expiration dates, or only store them for certain durations, and ensure a safe backup of clients’ data are in place. Comply with Sarbanes–Oxley Act. |
Data-protection policy among different enterprises.
| Sector | Data Protection Policy |
|---|---|
| Healthcare |
Patients’ data, including identifiable and nonidentified information, are handled and collected according to a set of rules. |
| Finance |
Customers’ data, such as names, contact information, such as email and phone numbers, and geographical information, such as addresses, are processed and handled according to certain rules. |
| Education |
Rules to protect students, staff, and faculty data, as well as secure handling and access to students’ data. |
| Aviation |
Passengers’ data are protected by rules that govern the secure processing of identifiable and nonidentified information, such as passport numbers, names of passengers, travel destinations, and so on. |
| E-commerce |
Personal data about consumers acquired from commercial sites and online business services are handled transparently and protected. |