Choice Architecture for Information Security
Choice Architecture for Information Security
批准号:
EP/K006568/1
负责人:
Aad Van Moorsel
金额:
$113.12万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2013
资助国家:
英国
项目状态:
已结题
起止时间:
2013 至 --
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Information security decisions are often made without any formal or rigorous backing. For instance, data about impact or likelihood of security breaches is rarely available. Careful prediction, for instance using monte carlo simulation, is often ommitted. It is natural, but also somewhat easy, to say that we need more rigorous techniques when we make information security decision. In the investigator's own work the following key challenges remain unresolved. First, rigorous approaches may introduce a false sense of security to decision-makers by not fully disclosing assumptions to decision makers (e.g, a model may assume a restricted attack scenario). Secondly, one may invest in perfecting the rigorous aspect without gaining too much more information; that is, the value of the added rigour may not lead to better decisions. This violates Buffett's mantra to better be approximately right than precisely wrong. Thirdly, decision-makers tend to ignore the information they receive through rigorous assessment, unless it validates the decision they already intended to make. To address these issues, we take inspiration from the work on nudging in the behavioural economics community, which provides a framework to influence decision makers as effectively as possible. In particular, we need tools and techniques to form a choice architecture tailored to information security. Information security has particular well-known characteristics, which we will exploit to provide sufficient rigour underlying the choice architecture. In particular, the project will establish rigorous mathematical approaches to include uncertainty about unknowns in our analysis, and will derived a theory about the 'value of rigour', allowing experts to judge which elements of rigour pay off further investment. We do our research in connection to one overarching information security issue of high practical importance, namely 'consumerization', that is, the use in the workplace of people's own technologies. This is possibly the main challenge that IT departments face in the coming years, to keep the workplace secure as the boundaries between work and personal life become more blurred. Depending on the enterprise, doing the "right thing" may result in different policies. The project will work with large organisations and SMEs through well-established channels. It will demonstrate the benefits of the advocated choice architecture through a case study in an SME. In very concrete terms, a possible outcome that an end user may experience as result of the project is as follows. Our research in the psychology of choice may reveal that a sense of ownership of data contributes to better security behaviour of employees. Quantitative techniques underlying the choice architecture measure the frequency with which an employee uses the phone for this purpose. Nudging tools are installed both as a mobile phone application and as a desktop tool for the CISO. For example, the tool for employees may be a mobile app that visually displays the consequence of data loss from the perspective of the employee, for instance in terms of how success in their job may be at stake. It makes strategic use of opt-outs and opt-ins to nudge the employee to balance security and productivity based on an underlying predictive model. The nudging tool for the CISO may be a desktop tool that provides the latest data and can be configured for a particular part of the organisation. The CISO tool carefully protects against a false sense of security by presenting the risk of unknowns and helps the CISO understand what data and which underlying assessment or decision-making would help improve the decision-making most.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/crisis.2013.6766353
发表时间:
2013
期刊:
影响因子:
--
作者:
[Alsuhibany S]
通讯作者:
Alsuhibany S
Optimisation of data collection strategies for model-based evaluation and decision-making
优化基于模型的评估和决策的数据收集策略
DOI:
10.1145/2746194.2746224
发表时间:
2015
期刊:
影响因子:
--
作者:
[Cain R]
通讯作者:
Cain R
DOI:
10.1007/978-3-642-40588-4_22
发表时间:
2013
期刊:
影响因子:
--
作者:
[Alsuhibany S]
通讯作者:
Alsuhibany S
Modelling and Analysis of Release Order of Security Algorithms Using Stochastic Petri Nets
基于随机Petri网的安全算法发布顺序建模与分析
DOI:
10.1109/ares.2013.58
发表时间:
2013
期刊:
影响因子:
--
作者:
[Alsuhibany S]
通讯作者:
Alsuhibany S
Sensible Privacy
合理的隐私
DOI:
10.1145/2665943.2665965
发表时间:
2014
期刊:
影响因子:
--
作者:
[Arief B]
通讯作者:
Arief B
共 7 条
UKFIN
-
批准号:EP/W034042/1
-
项目类别:Research Grant
-
资助金额:$260.47万
-
财政年份:2022
-
负责人:Aad Van Moorsel
-
依托单位:
AGENCY: Assuring Citizen Agency in a World with Complex Online Harms
-
批准号:EP/W032481/2
-
项目类别:Research Grant
-
资助金额:$340.75万
-
财政年份:2022
-
负责人:Aad Van Moorsel
-
依托单位:
AGENCY: Assuring Citizen Agency in a World with Complex Online Harms
-
批准号:EP/W032481/1
-
项目类别:Research Grant
-
资助金额:$355.9万
-
财政年份:2022
-
负责人:Aad Van Moorsel
-
依托单位:
FinTrust: Trust Engineering for the Financial Industry
-
批准号:EP/R033595/1
-
项目类别:Research Grant
-
资助金额:$133.43万
-
财政年份:2018
-
负责人:Aad Van Moorsel
-
依托单位:
Hyper-privacy: Case of Domestic Violence (Hyper-DoVe)
-
批准号:EP/K012649/1
-
项目类别:Research Grant
-
资助金额:$15.46万
-
财政年份:2013
-
负责人:Aad Van Moorsel
-
依托单位:
Academic Centre of Excellence in Cyber Security Research - Newcastle University
-
批准号:EP/L002213/1
-
项目类别:Research Grant
-
资助金额:$5.17万
-
财政年份:2013
-
负责人:Aad Van Moorsel
-
依托单位:
Cybercrime Network
-
批准号:EP/K003410/1
-
项目类别:Research Grant
-
资助金额:$12.85万
-
财政年份:2012
-
负责人:Aad Van Moorsel
-
依托单位:
Economics-Inspired Instant Trust Mechanisms for the Service Provision Industry
-
批准号:EP/F066937/1
-
项目类别:Research Grant
-
资助金额:$20.8万
-
财政年份:2008
-
负责人:Aad Van Moorsel
-
依托单位:
海外基金