Productive Security - Improving security compliance and productivity through measurement
Productive Security - Improving security compliance and productivity through measurement
批准号:
EP/K006517/1
负责人:
Martina Angela Sasse
金额:
$148.86万
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2012
资助国家:
英国
项目状态:
已结题
起止时间:
2012 至 --
中文摘要
点击翻译按钮获取中文摘要
英文摘要
There has been a growing body of evidence that security policies and controls are not effective because employees either can't, or won't, comply. A key reason for non-compliance is the workload and complexity of security controls chosen - employees simply cannot cope with an ever-increasing number of ever-longer and more complex passwords. Yet most security-decision-makers do not factor the impact on employees, their tasks, and company's business processes, into their decision about which security controls to put in place. Current attempts to 'edcuate' employees about the need for security are largely ineffective because they simply push more information on people who are already overworked.And even in organisations with a high security awareness, non-compliance can be observed because security policy cause excessive friction, or are not agile enough to meet the needs of the business.There exists a strong requirement for a structured, scientifically-grounded decision-making framework into which existing data can be inserted, alongside the key 'missing link' measurements of employee's workload, risk perception, and resulting security behaviours. The project will work with at least two major companies to collect such data, and build a model of that allows security decision-makers to 'calculate' the impact of the security controls on employees and business processes, and balance them against the risk mitigation the security control achieves. A further innovative step in this proposal is that well-chosen security controls could make contributions to the business process beyond security, if the imformation they provide can be used to improve quality of products or services - hence the title of the project.
期刊论文(9)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Awareness is only the first step
意识只是第一步
DOI:
--
发表时间:
2015
期刊:
影响因子:
--
作者:
[Beyer M]
通讯作者:
Beyer M
DOI:
10.1109/sp.2017.65
发表时间:
2017-05
期刊:
2017 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
作者:
[Ruba Abu-Salma;M. Sasse;Joseph Bonneau;A. Danilova;Alena Naiakshina;Matthew Smith]
通讯作者:
Ruba Abu-Salma;M. Sasse;Joseph Bonneau;A. Danilova;Alena Naiakshina;Matthew Smith
Combining Qualitative Coding and Sentiment Analysis: Deconstructing Perceptions of Usable Security in Organisations
结合定性编码和情感分析:解构组织中可用安全的看法
DOI:
--
发表时间:
2016
期刊:
影响因子:
--
作者:
[Becker I]
通讯作者:
Becker I
The Security Blanket of the Chat World: An Analytic Evaluation and a User Study of Telegram
聊天世界的安全毯:Telegram 的分析评估和用户研究
DOI:
10.14722/eurousec.2017.23006
发表时间:
2017
期刊:
影响因子:
--
作者:
[Abu-Salma R]
通讯作者:
Abu-Salma R
Finding Security Champions in Blends of Organisational Culture
在组织文化的融合中寻找安全冠军
DOI:
10.14722/eurousec.2017.23007
发表时间:
2017
期刊:
影响因子:
--
作者:
[Becker I]
通讯作者:
Becker I
共 7 条
Easy Expression of Authorisation Policies
-
批准号:EP/D052424/1
-
项目类别:Research Grant
-
资助金额:$11.75万
-
财政年份:2006
-
负责人:Martina Angela Sasse
-
依托单位:
海外基金