Learning from "Shadow Security": Why understanding non-compliant behaviors provides the basis for effective security

Learning from "Shadow Security": Why understanding non-compliant behaviors provides the basis for effective security
复制标题

向“影子安全”学习:为什么了解不合规行为为有效安全提供了基础

DOI:
--
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
M. Sasse
M. Sasse
中科院分区:
--
文献类型:
--
作者:
I. Kirlappos;S. Parkin;M. Sasse

文献摘要

参考文献

被引文献

相似文献

在过去的十年中,安全研究人员和从业人员试图了解为什么员工不遵守组织的安全政策和机制。过去的研究把服从看作是一个二元的决定:人们服从,或者他们不服从。根据我们对118名个人(大型跨国组织的员工)关于安全违规行为的深入采访的分析,出现了第三种反应:影子安全。这描述了这样一种情况,即有安全意识的员工认为他们不能遵守规定的安全策略,他们创建了一个更合适的替代方案,以替代组织的正式安全人员创建的策略和机制。这些解决方法通常对官方安全和更高管理层不可见-因此称为“影子安全”。理论上,它们可能不像“官方”政策那样安全,但它们反映了员工在完成工作和管理他们所了解的资产所面临的风险之间所能找到的最佳妥协。我们的结论是,而不是试图“消灭”影子安全实践,组织应该从中学习:他们提供了一个起点“可行的”安全:解决方案,提供有效的安全和适合组织的业务,而不是阻碍它。
Over the past decade, security researchers and practitioners have tried to understand why employees do not comply with organizational security policies and mechanisms. Past re-search has treated compliance as a binary decision: people comply, or they do not. From our analysis of 118 in-depth interviews with individuals (employees in a large multinational organization) about security non-compliance, a 3rd response emerges: shadow security. This describes the instances where security-conscious employees who think they cannot comply with the prescribed security policy create a more fitting alter-native to the policies and mechanisms created by the organization’s official security staff. These workarounds are usually not visible to official security and higher management – hence ‘shadow security’. They may not be as secure as the ‘official’ policy would be in theory, but they reflect the best compromise staff can find between getting the job done and managing the risks that the assets they understand face. We conclude that rather than trying to ‘stamp out’ shadow security practices, organizations should learn from them: they provide a starting point ‘workable’ security: solutions that offer effective security and fit with the organization’s business, rather than impede it.
用户如何绕过访问控制 - 以及原因:授权问题对个人和组织的影响
DOI: --
发表时间: 2013
期刊: European Conference on Information Systems (ECIS) 2013 Completed Research
影响因子: --
作者:
Bartsch S
通讯作者: Bartsch S