A Case for Societal Digital Security Culture

Angın, Pelin
Information and communication technology systems, such as remote health care monitoring and smart mobility applications, have become indispensable parts of our lives. Security vulnerabilities in these systems could cause financial losses, privacy/safety compromises, and operational interruptions. This paper demonstrates through examples, that technical security solutions for these information systems, alone, are not sufficient to protect individuals and their assets from attacks. It proposes to complement (usable) technical solutions with Societal Digital Security Culture (SDSC): collective knowledge, common practices, and intuitive common behavior about digital security that the members of a society share. The paper also suggests a set of approaches for improving SDSC in a society and demonstrates using a case study how the suggested approaches could be integrated to compose a plan for improving SDSC.


An intelligent security architecture for sdn-assisted iot networks
Demirpolat, Ahmed; Angın, Pelin; Department of Computer Engineering (2021-1-26)
The rise of the Internet of Things (IoT) paradigm in the past decade has had a significant impact on all aspects of our lives through the many use cases it has made possible, including smart farming, smart homes, and remote healthcare services, among many others. While the number of smart devices and utilization scenarios aimed at supporting them grow exponentially, the large attack surface created by the interconnectivity of millions of these devices is a concerning aspect that needs to be addressed with i...
A Decision Support System for Optimal Selection of Enterprise Information Security Preventative Actions
Sonmez, Ferda Ozdemir; Günel Kılıç, Banu (2021-09-01)
Types and complexity of information security related vulnerabilities are growing rapidly and present numerous challenges to the enterprises. One of the key challenges is to identify the optimal set of precautions with limited budget. Despite the fact that majority of enterprises have a budget constraint for installing and maintaining the protection systems, the majority of the previous work only focus on prioritization of security targets and do not consider the preventative actions and budget constraints. ...
A Conceptual Model for a Metric Based Framework for the Monitoring of Information Security Tasks’ Efficiency
Sönmez, Ferda Özdemir (Elsevier BV; 2019)
Information Security Governance Systems are not adequate to measure the effectiveness and efficiency of security tasks for the enterprises. Although some of the systems offer ways for measurement, they still need the definition of measurement objectives and metrics. This study proposes a conceptual framework mode which has human and tool/process related metrics. This system also allows the collection of evidence data for security-related tasks and ways to motivate the security staff to provide a more produc...
A Systematic Literature Review on Health Recommender Systems
Sezgin, Emre; Özkan Yıldırım, Sevgi (2013-11-23)
Health Information Systems are becoming an important platform for healthcare services. In this context, Health Recommender Systems (HRS) are presented as complementary tools in decision making processes in health care services. Health Recommender Systems increase usability of technologies and reduce information overload in processes. In this paper, a literature review was conducted by following a review procedure. Major approaches in HRS were outlined and findings were discussed. The paper presented current...
A novel user activity prediction model for context aware computing systems
Peker, Serhat; Koçyiğit, Altan; Department of Information Systems (2011)
In the last decade, with the extensive use of mobile electronic and wireless communication devices, there is a growing need for context aware applications and many pervasive computing applications have become integral parts of our daily lives. Context aware recommender systems are one of the popular ones in this area. Such systems surround the users and integrate with the environment; hence, they are aware of the users' context and use that information to deliver personalized recommendations about everyday ...
