Skip to main content

A Survey of Cyber Security Practices in Small Businesses

  • Conference paper
  • First Online:
National Cyber Summit (NCS) Research Track (NCS 2019)

Part of the book series: Advances in Intelligent Systems and Computing ((AISC,volume 1055))

Included in the following conference series:

Abstract

Small businesses are a unique class of organization with challenging cyber security problems that are frequently overlooked. These firms are being increasingly targeted for cyber-attack. These firms are particularly vulnerable to cyber-attack due to the often-valuable information they handle coupled with overworked and undertrained IT support. The University of Alabama in Huntsville is conducting an on-going survey of the cyber security practices of small businesses seeking to implement the NIST SP 800-171 cyber security standard. The data gathered indicates that small businesses in this field are likely to engage in poor security practices arising from common cyber security misconceptions.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 84.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 109.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

References

  1. National Institute of Standards and Technology: NIST Special Publication 800-171 Revision 1: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r1.pdf. Accessed 27 Feb 2019

  2. National Institute of Standards and Technology: NIST Handbook 162: NIST MEP Cybersecurity Self-assessment Handbook For Assessing NIST SP 800-171 Security Requirements in Response to DFARS Cybersecurity Requirements. https://nvlpubs.nist.gov/nistpubs/hb/2017/nist.hb.162.pdf. Accessed 27 Feb 2019

  3. National Institute of Standards and Technology: DFARS Cybersecurity Requirements. https://www.nist.gov/mep/cybersecurity-resources-manufacturers/dfars800-171-compliance. Accessed 27 Feb 2019

  4. US Department of Defense: Defense Federal Acquisition Supplement, 252.204-7012. https://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm#252.204-7012. Accessed 3 Mar 2019

  5. Educause Review: CUI Requirements in Federal Contracts Aren’t FAR Away. https://er.educause.edu/blogs/2018/5/cui-requirements-in-federal-contracts-arent-far-away. Accessed 3 Mar 2019

  6. PCI Security Standards Council: Payment Card Industry (PCI) Data Security Standard Version 3.2.1. https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf?agreement=true&time=1553228375592. Accessed 3 Mar 2019

  7. Rosenburg, J.: Vulnerable to attack: businesses should boost cyber defenses. https://www.fifthdomain.com/industry/2019/03/13/vulnerable-to-attack-businesses-should-boost-cyber-defenses. Accessed 21 Mar 2019

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Eric Imsand .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2020 Springer Nature Switzerland AG

About this paper

Check for updates. Verify currency and authenticity via CrossMark

Cite this paper

Imsand, E., Tucker, B., Paxton, J., Graves, S. (2020). A Survey of Cyber Security Practices in Small Businesses. In: Choo, KK., Morris, T., Peterson, G. (eds) National Cyber Summit (NCS) Research Track. NCS 2019. Advances in Intelligent Systems and Computing, vol 1055. Springer, Cham. https://doi.org/10.1007/978-3-030-31239-8_4

Download citation

Publish with us

Policies and ethics