"Shadow security" as a tool for the learning organization

"Shadow security" as a tool for the learning organization
复制标题

“影子安全”作为学习型组织的工具

DOI:
10.1145/2738210.2738216
复制
发表时间:
2015
期刊:
SIGCAS Comput. Soc.
影响因子:
--
通讯作者:
M. Sasse
M. Sasse
中科院分区:
--
文献类型:
--
作者:
I. Kirlappos;S. Parkin;M. Sasse

文献摘要

被引文献

相似文献

传统上,组织通过员工应遵守的策略和机制来管理信息安全。不遵守安全规定被认为是不可取的,并且常常以制裁相威胁来阻止这种行为。但在最近的一项研究中,我们确定了第三类员工安全行为:影子安全。这包括员工为确保实现主要业务目标而设计的变通办法;他们还制定自己的安全措施来应对他们所了解的风险。虽然不符合官方政策,有时也不像员工想象的那么安全,但影子安全实践反映了员工在安全和“完成工作”之间找到的工作妥协。我们通过讨论来自不同组织的新访谈研究的结果,在本文中补充了这一见解。我们确定了其他影子安全实践,并展示了如何在学习型组织的框架内将它们转变为有效且提高生产力的安全解决方案。
Traditionally, organizations manage information security through policies and mechanisms that employees are expected to comply with. Non-compliance with security is regarded as undesirable, and often sanctions are threatened to deter it. But in a recent study, we identified a third category of employee security behavior: shadow security. This consists of workarounds employees devise to ensure primary business goals are achieved; they also devise their own security measures to counter the risks they understand. Whilst not compliant with official policy, and sometimes not as secure as employees think, shadow security practices reflect the working compromise staff find between security and "getting the job done". We add to this insight in this paper by discussing findings from a new interview study in a different organization. We identified additional shadow security practices, and show how they can be transformed into effective and productivity-enabling security solutions, within the framework of a learning organization.