{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T21:46:40Z","timestamp":1783028800242,"version":"3.54.6"},"reference-count":41,"publisher":"Emerald","issue":"2","license":[{"start":{"date-parts":[[2012,4,27]],"date-time":"2012-04-27T00:00:00Z","timestamp":1335484800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012,4,27]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-heading\">Purpose<\/jats:title><jats:p>The purpose of this paper is to examine social media security risks and existing mitigation techniques in order to gather insights and develop best practices to help organizations address social media security risks more effectively.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title><jats:p>This paper begins by reviewing the disparate discussions in literature on social media security risks and mitigation techniques. Based on an extensive review, some key insights were identified and summarized to help organizations more effectively address social media security risks.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Findings<\/jats:title><jats:p>Many organizations do not have effective social media security policy in place and are unsure of how to develop effective social media security strategies to mitigate social media security risks. This paper provides guidance to organizations to mitigate social media security risks that may threaten the organizations.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title><jats:p>The paper consolidates the fragmented discussion in literature and provides an in\u2010depth review of social media security risks and mitigation techniques. Practical insights are identified and summarized from an extensive literature review. Sharing these insights has the potential to encourage more discussion on best practices for reducing the risks of social media to organizations.<\/jats:p><\/jats:sec>","DOI":"10.1108\/13287261211232180","type":"journal-article","created":{"date-parts":[[2012,5,26]],"date-time":"2012-05-26T07:07:40Z","timestamp":1338016060000},"page":"171-180","source":"Crossref","is-referenced-by-count":43,"title":["A review of social media security risks and mitigation techniques"],"prefix":"10.1108","volume":"14","author":[{"given":"Wu","family":"He","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"140","reference":[{"key":"key2022022020483885700_b1","doi-asserted-by":"crossref","unstructured":"Abraham, S. and Chengalur\u2010Smith, I. (2010), \u201cAn overview of social engineering malware: trends, tactics, and implications\u201d, Technology in Society, Vol. 32 No. 3, pp. 183\u201096.","DOI":"10.1016\/j.techsoc.2010.07.001"},{"key":"key2022022020483885700_b2","unstructured":"Aytes, K. and Connolly, T. (2003), \u201cA research model for investigating human behavior related to computer security\u201d, AMCIS 2003 Proceedings, pp. 2027\u201031."},{"key":"key2022022020483885700_b3","unstructured":"Blue Ocean (2011), Social Media Security Policy, available at: www.blueoceantechnologies.net\/BlueOceanTechnologiesSocialMediaSecurityPolicy.pdf (accessed 12 November)."},{"key":"key2022022020483885700_b4","unstructured":"CDC (2009), Social Media Security Mitigations, available at: www.cdc.gov\/socialmedia\/tools\/guidelines\/pdf\/securitymitigations.pdf (accessed 12 October 2011)."},{"key":"key2022022020483885700_b5","unstructured":"Chi, M. (2011), \u201cSecurity policy and social media use\u201d, available at: www.sans.org\/reading_room\/whitepapers\/policyissues\/reducing\u2010risks\u2010social\u2010media\u2010organization_33749 (accessed 9 November)."},{"key":"key2022022020483885700_b7","unstructured":"Cisco Systems (2008a), \u201cData leakage worldwide: the effectiveness of corporate security policies\u201d, available at: www.cisco.com\/en\/US\/solutions\/collateral\/ns170\/ns896\/ns895\/Cisco_STL_Data_Leakage_2008_.pdf (accessed 16 November 2011)."},{"key":"key2022022020483885700_b6","unstructured":"Cisco Systems (2008b), \u201cData leakage worldwide: the effectiveness of security policies\u201d, available at: www.cisco.com\/en\/US\/solutions\/collateral\/ns170\/ns896\/ns895\/white_paper_c11\u2010503131.pdf (accessed 9 November 2011)."},{"key":"key2022022020483885700_b8","unstructured":"Clavette, L., Faggard, D., Bove, P. and Fordham, J. (2009), New Media and the Air Force, United States Air Force, available at: www.af.mil\/shared\/media\/document\/AFD\u2010090406\u2010036.pdf (accessed 26 November 2011)."},{"key":"key2022022020483885700_b9","unstructured":"Clearswift (2011), \u201cWork life web 2011\u201d, available at: https:\/\/info.clearswift.com\/express\/clients\/clearhq\/papers\/Clearswift_report_WorkLifeWeb_2011.pdf (accessed 12 November)."},{"key":"key2022022020483885700_b10","unstructured":"Curry, S. (2011), \u201cThe weakest link is the human link\u201d, available at: www.securityweek.com\/weakest\u2010link\u2010human\u2010link (accessed 16 November)."},{"key":"key2022022020483885700_b11","doi-asserted-by":"crossref","unstructured":"Davinson, N. and Sillence, E. (2010), \u201cIt won't happen to me: promoting secure behaviour among internet users\u201d, Computers in Human Behavior, Vol. 26 No. 6, pp. 1739\u201047.","DOI":"10.1016\/j.chb.2010.06.023"},{"key":"key2022022020483885700_b12","unstructured":"Federal CIO Council (2009), Guidelines for Secure Use of Social Media by Federal Departments and Agencies, available at: www.cio.gov\/Documents\/Guidelines_for_Secure_Use_Social_Media_v01\u20100.pdf (accessed 20 November 2011)."},{"key":"key2022022020483885700_b13","unstructured":"Ghosh, S. (2011), \u201cSeven social media security best practices\u201d, available at: http:\/\/searchsecurity.techtarget.in\/tip\/Seven\u2010social\u2010media\u2010security\u2010best\u2010practices (accessed 16 November)."},{"key":"key2022022020483885700_b14","unstructured":"Granger, S. (2002), Social Engineering Fundamentals, Part II: Combat Strategies, available at: www.securityfocus.com\/infocus\/1533 (accessed 17 November 2011)."},{"key":"key2022022020483885700_b15","doi-asserted-by":"crossref","unstructured":"Hayden, L. (2009), \u201cHuman information security behaviors: differences across geographies and cultures in a global user survey\u201d, Proceedings of the American Society for Information Science and Technology Annual Meeting, Vancouver, BC, available at: www.asis.org\/Conferences\/AM09\/open\u2010proceedings\/papers\/2.xml (accessed 16 November 2011).","DOI":"10.1002\/meet.2009.145046022"},{"key":"key2022022020483885700_b16","doi-asserted-by":"crossref","unstructured":"Huber, M., Kowalskiy, S., Nohlbergz, M. and Tjoa, S. (2009), \u201cTowards automating social engineering using social networking sites\u201d, Proceedings of International Conference on Computational Science and Engineering.","DOI":"10.1109\/CSE.2009.205"},{"key":"key2022022020483885700_b17","unstructured":"Intel (2009), Prioritizing Information Security Risks with Threat Agent Risk, available at: ftp:\/\/download.intel.com\/it\/pdf\/Prioritizing_Info_Security_Risks_with_TARA.pdf (accessed 16 November 2011)."},{"key":"key2022022020483885700_b18","unstructured":"ISACA (2010), \u201cTop five social media risks for business: new ISACA white paper\u201d, available at: www.isaca.org\/About\u2010ISACA\/Press\u2010room\/News\u2010Releases\/2010\/Pages\/Top\u2010Five\u2010Social\u2010Media\u2010Risks\u2010for\u2010Business\u2010New\u2010ISACA\u2010White\u2010Paper.aspx (accessed 16 November 2011)."},{"key":"key2022022020483885700_b19","unstructured":"Ivaturi, K. and Janczewski, L. (2011), \u201cA taxonomy for social engineering attacks\u201d, CONF\u2010IRM 2011 Proceedings, Paper 15, available at: http:\/\/aisel.aisnet.org\/confirm2011\/15 (accessed 16 November)."},{"key":"key2022022020483885700_b20","doi-asserted-by":"crossref","unstructured":"Jagatic, T., Johnson, N., Jakobsson, M. and Menczer, F. (2006), \u201cSocial phishing\u201d, Communications of the ACM, Vol. 50 No. 10.","DOI":"10.1145\/1290958.1290968"},{"key":"key2022022020483885700_b21","doi-asserted-by":"crossref","unstructured":"Jakobsson, M. and Myers, S. (2006), Phishing and Countermeasures: Understanding the Increasing Problem of Electronic Identity Theft, Wiley, Hoboken, NJ.","DOI":"10.1002\/0470086106"},{"key":"key2022022020483885700_b22","doi-asserted-by":"crossref","unstructured":"Kaplan, M. and Haenlein, M. (2010), \u201cUsers of the world, unite! The challenges and opportunities of social media\u201d, Business Horizons, Vol. 53 No. 1, pp. 59\u201068.","DOI":"10.1016\/j.bushor.2009.09.003"},{"key":"key2022022020483885700_b23","unstructured":"Kaspersky Labs (2009), Kaspersky Security Bulletin: Malware Evolution 2008, available at: www.securelist.com\/en\/analysis?pubid=204792051 (accessed 16 November 2011)."},{"key":"key2022022020483885700_b24","unstructured":"McAfee (2010), 2011 Threats Predictions, available at: http:\/\/161.69.13.40\/us\/resources\/reports\/rp\u2010threat\u2010predictions\u20102011.pdf (accessed 16 November 2011)."},{"key":"key2022022020483885700_b25","unstructured":"MWR InfoSecurity (2011), Is Social Media One of Your Vulnerabilities?, available at: www.mwrinfosecurity.com\/files\/Events\/mwri_social\u2010media\u2010security_2011\u201001\u201028.pdf (accessed 23 November)."},{"key":"key2022022020483885700_b26","doi-asserted-by":"crossref","unstructured":"Peltier, T.R. (2006), \u201cSocial engineering: concepts and solutions\u201d, Information Systems Security, Vol. 15 No. 5, pp. 13\u201021.","DOI":"10.1201\/1086.1065898X\/46353.15.4.20060901\/95427.3"},{"key":"key2022022020483885700_b27","unstructured":"Perez, S. (2009), \u201cTop 8 web 2.0 security threats\u201d, available at: www.readwriteweb.com\/enterprise\/2009\/02\/top\u20108\u2010web\u201020\u2010security\u2010threats.php (accessed 25 November 2011)."},{"key":"key2022022020483885700_b28","unstructured":"Ponemon (2011), Ponemon Institute Research Report: Global Survey on Social Media Risks Survey of IT & IT Security Practitioners, available at: www.websense.com\/content\/ponemon\u2010institute\u2010research\u2010report\u20102011.aspx (accessed 23 November)."},{"key":"key2022022020483885700_b29","unstructured":"Qualman, E. (2009), Socialnomics: How Social Media Transforms the Way We Live and Do Business, Wiley, Hoboken, NJ."},{"key":"key2022022020483885700_b30","unstructured":"Safko, L. and Brake, D. (2009), The Social Media Bible: Tactics, Tools, and Strategies for Business Success, Wiley, Hoboken, NJ."},{"key":"key2022022020483885700_b31","unstructured":"SANS Institute (2011), Password Policy, available at: www.sans.org\/security\u2010resources\/policies\/Password_Policy.pdf (accessed 23 November)."},{"key":"key2022022020483885700_b32","unstructured":"Scott, D.M. (2008), \u201cThe US air force: armed with social media\u201d, available at: www.webinknow.com\/2008\/12\/the\u2010us\u2010air\u2010force\u2010armed\u2010with\u2010social\u2010media.html (accessed 23 November 2011)."},{"key":"key2022022020483885700_b33","unstructured":"Sherry, D. (2008), \u201cHow to implement and enforce a social networking security policy\u201d, available at: http:\/\/searchsecurity.techtarget.com\/tip\/How\u2010to\u2010implement\u2010and\u2010enforce\u2010a\u2010social\u2010networking\u2010security\u2010policy (accessed 23 November 2011)."},{"key":"key2022022020483885700_b35","doi-asserted-by":"crossref","unstructured":"Son, J.Y. (2011), \u201cOut of fear or desire? Toward a better understanding of employees' motivation to follow IS security policies\u201d, Information & Management, Vol. 48 No. 7, pp. 296\u2010302.","DOI":"10.1016\/j.im.2011.07.002"},{"key":"key2022022020483885700_b34","unstructured":"Sophos (2011), \u201cExample social media security policy\u201d, available at: www.sophos.com\/sophos\/docs\/eng\/smst\/sophos\u2010example\u2010social\u2010media\u2010security\u2010policy.pdf (accessed 23 November)."},{"key":"key2022022020483885700_b36","doi-asserted-by":"crossref","unstructured":"Stanton, J.M., Stam, K.R., Mastrangelo, P. and Jolton, J. (2005), \u201cAnalysis of end user security behaviors\u201d, Computers and Security, Vol. 24 No. 2, pp. 124\u201033.","DOI":"10.1016\/j.cose.2004.07.001"},{"key":"key2022022020483885700_b37","unstructured":"Symantec (2011a), \u201cSocial media protection flash poll global results\u201d, available at: www.slideshare.net\/symantec\/symantec\u20102011\u2010social\u2010media\u2010protection\u2010flash\u2010poll\u2010global\u2010results (accessed 23 November)."},{"key":"key2022022020483885700_b38","unstructured":"Symantec (2011b), \u201cSymantec enterprise vault 10 reduces the risks of using social media tools for business\u201d, available at: www.symantec.com\/about\/news\/release\/article.jsp?prid=20110801_02 (accessed 23 November)."},{"key":"key2022022020483885700_b39","unstructured":"Vroom, C. and von Solms, R. (2004), \u201cTowards information security behavioral compliance\u201d, Information Management & Computer Security, Vol. 6 No. 4, pp. 167\u201073."},{"key":"key2022022020483885700_b40","unstructured":"Zeltser, L. (2011), \u201cMonitoring social media for security references to your organization\u201d, available at: http:\/\/isc.sans.edu\/diary.html?storyid=10921 (accessed 23 November)."},{"key":"key2022022020483885700_b41","unstructured":"Zhang, H. (2011), \u201cSocial media: a hacker's secret weapon for accessing your network\u201d, available at: http:\/\/esj.com\/Articles\/2011\/10\/31\/Social\u2010Media\u2010Hackers\u2010Secret\u2010Weapon.aspx?Page=1 (accessed 23 November)."}],"container-title":["Journal of Systems and Information Technology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/13287261211232180","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/13287261211232180\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/13287261211232180\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T00:24:24Z","timestamp":1753403064000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/jsit\/article\/14\/2\/171-180\/249516"}},"subtitle":[],"editor":[{"given":"Helene","family":"Delerue","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"editor"}]}],"short-title":[],"issued":{"date-parts":[[2012,4,27]]},"references-count":41,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2012,4,27]]}},"alternative-id":["10.1108\/13287261211232180"],"URL":"https:\/\/doi.org\/10.1108\/13287261211232180","relation":{},"ISSN":["1328-7265"],"issn-type":[{"value":"1328-7265","type":"print"}],"subject":[],"published":{"date-parts":[[2012,4,27]]}}}