Shifting the Blame? Investigation of User Compliance with Digital Payment Regulations

Shifting the Blame? Investigation of User Compliance with Digital Payment Regulations
复制标题

转移责任?

DOI:
10.1007/978-3-030-60527-8_5
复制
发表时间:
2021
期刊:
Int. J. Enterp. Inf. Syst.
影响因子:
--
通讯作者:
S. Zee
S. Zee
中科院分区:
--
文献类型:
--
作者:
S. Zee

文献摘要

被引文献

相似文献

用户在大多数成功的网络攻击中发挥着关键作用。遵守信息安全准则可以导致更安全的数字行为,从而减少成功攻击的机会。由于客户合规性对银行尤其重要,荷兰银行协会(DBA)为客户制定并实施了一套五项安全指南。每个准则都分为几个具体的行动,客户需要采取,以遵守。不遵守规定可能会导致疏忽索赔和成为网络犯罪受害者时的经济损失。只有当人们意识到它们的存在并大多数人遵守时,这种安全准则才能成功。在一项用户调查(n= 119)中,我们测试了情况是否如此。结果表明,只有四分之一的样本(24.4%)知道存在的指导方针。当被问及是否遵守五项一般准则时,不到四分之一(23.5%)的参与者报告遵守了所有五项准则。当被问及遵守这些准则所需的所有具体行动时,只有3.4%的人报告完全遵守。一项更深入的分析表明,对准则的了解并没有增加遵守情况。本文的研究结果支持了安全文献中的最新发现,即知识和意识本身并不能增加安全的数字行为。总的来说,本研究中显示的DBA安全指南的低意识和更低的合规率表明,银行可能不公平地将责任转移到客户身上。
Users play a crucial role in the majority of successful cyberattacks. Compliance with information security guidelines can lead to more secure digital behavior and thereby reduce the chance of successful attacks. Since customer compliance is especially relevant for banks, the Dutch Banking Association (DBA) has developed and implemented a set of five security guidelines for customers. Each guideline is split into several specific actions that customers need to undertake in order to comply. Failure to comply can lead to a negligence claim and financial losses when falling victim to cybercrime. Such security guidelines are only successful if people are aware of their existence and mostly comply. In a user survey (n= 119) we tested whether this was the case. Results indicate that only a quarter of our sample (24.4%) was aware guidelines existed. When asked about compliance with the five general guidelines, less than a quarter (23.5%) of participants reported following all five guidelines. When asked about compliance with all specified actions needed to comply with these guidelines, only 3.4% reported complete compliance. A more in-depth analysis revealed that awareness of the guidelines did not increase compliance. The findings from this paper support recent findings in the security literature that knowledge and awareness alone do not increase secure digital behavior. Taken together, the low awareness and even lower compliance rates with the DBA security guidelines demonstrated in this study suggest that banks may be unfairly shifting the blame towards their customers.