Learning from "Shadow Security": Why understanding non-compliant behaviors provides the basis for effective security
Learning from "Shadow Security": Why understanding non-compliant behaviors provides the basis for effective security
复制标题
向“影子安全”学习:为什么了解不合规行为为有效安全提供了基础
DOI:
--
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
M. Sasse
中科院分区:
文献类型:
--
作者:
I. Kirlappos;S. Parkin;M. Sasse
Over the past decade, security researchers and practitioners have tried to understand why employees do not comply with organizational security policies and mechanisms. Past re-search has treated compliance as a binary decision: people comply, or they do not. From our analysis of 118 in-depth interviews with individuals (employees in a large multinational organization) about security non-compliance, a 3rd response emerges: shadow security. This describes the instances where security-conscious employees who think they cannot comply with the prescribed security policy create a more fitting alter-native to the policies and mechanisms created by the organization’s official security staff. These workarounds are usually not visible to official security and higher management – hence ‘shadow security’. They may not be as secure as the ‘official’ policy would be in theory, but they reflect the best compromise staff can find between getting the job done and managing the risks that the assets they understand face. We conclude that rather than trying to ‘stamp out’ shadow security practices, organizations should learn from them: they provide a starting point ‘workable’ security: solutions that offer effective security and fit with the organization’s business, rather than impede it.
DOI:
--
发表时间:
2013
期刊:
European Conference on Information Systems (ECIS) 2013 Completed Research
影响因子:
--
作者:
Bartsch S
通讯作者:
Bartsch S