Productive Security - Improving security compliance and productivity through measurement
生产安全 - 通过测量提高安全合规性和生产效率
基本信息
- 批准号:EP/K006517/1
- 负责人:
- 金额:$ 148.86万
- 依托单位:
- 依托单位国家:英国
- 项目类别:Research Grant
- 财政年份:2012
- 资助国家:英国
- 起止时间:2012 至 无数据
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
There has been a growing body of evidence that security policies and controls are not effective because employees either can't, or won't, comply. A key reason for non-compliance is the workload and complexity of security controls chosen - employees simply cannot cope with an ever-increasing number of ever-longer and more complex passwords. Yet most security-decision-makers do not factor the impact on employees, their tasks, and company's business processes, into their decision about which security controls to put in place. Current attempts to 'edcuate' employees about the need for security are largely ineffective because they simply push more information on people who are already overworked.And even in organisations with a high security awareness, non-compliance can be observed because security policy cause excessive friction, or are not agile enough to meet the needs of the business.There exists a strong requirement for a structured, scientifically-grounded decision-making framework into which existing data can be inserted, alongside the key 'missing link' measurements of employee's workload, risk perception, and resulting security behaviours. The project will work with at least two major companies to collect such data, and build a model of that allows security decision-makers to 'calculate' the impact of the security controls on employees and business processes, and balance them against the risk mitigation the security control achieves. A further innovative step in this proposal is that well-chosen security controls could make contributions to the business process beyond security, if the imformation they provide can be used to improve quality of products or services - hence the title of the project.
越来越多的证据表明,安全策略和控制措施是无效的,因为员工不能或不愿遵守。不合规的一个关键原因是所选安全控制的工作量和复杂性-员工根本无法科普越来越多的更长、更复杂的密码。然而,大多数安全决策者在决定实施哪些安全控制时,并没有考虑到对员工、他们的任务和公司业务流程的影响。目前试图“教育”员工对安全的需求基本上是无效的,因为他们只是把更多的信息推给那些已经超负荷工作的人。即使在具有高度安全意识的组织中,也可以观察到不合规的情况,因为安全策略会导致过度摩擦,或者不够灵活,无法满足业务需求。这是一个基于科学的决策框架,可以将现有数据插入其中,以及对员工工作量、风险感知和由此产生的安全行为的关键“缺失环节”测量。该项目将与至少两家大公司合作收集此类数据,并建立一个模型,允许安全决策者“计算”安全控制对员工和业务流程的影响,并将其与安全控制实现的风险缓解进行平衡。本提案中的另一个创新步骤是,如果精心选择的安全控制提供的信息可以用于提高产品或服务的质量,那么它们可以对业务流程做出超越安全的贡献-因此该项目的名称。
项目成果
期刊论文数量(9)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Obstacles to the Adoption of Secure Communication Tools
- DOI:10.1109/sp.2017.65
- 发表时间:2017-05
- 期刊:
- 影响因子:0
- 作者:Ruba Abu-Salma;M. Sasse;Joseph Bonneau;A. Danilova;Alena Naiakshina;Matthew Smith
- 通讯作者:Ruba Abu-Salma;M. Sasse;Joseph Bonneau;A. Danilova;Alena Naiakshina;Matthew Smith
Combining Qualitative Coding and Sentiment Analysis: Deconstructing Perceptions of Usable Security in Organisations
结合定性编码和情感分析:解构组织中可用安全的看法
- DOI:
- 发表时间:2016
- 期刊:
- 影响因子:0
- 作者:Becker I
- 通讯作者:Becker I
The Security Blanket of the Chat World: An Analytic Evaluation and a User Study of Telegram
聊天世界的安全毯:Telegram 的分析评估和用户研究
- DOI:10.14722/eurousec.2017.23006
- 发表时间:2017
- 期刊:
- 影响因子:0
- 作者:Abu-Salma R
- 通讯作者:Abu-Salma R
Finding Security Champions in Blends of Organisational Culture
在组织文化的融合中寻找安全冠军
- DOI:10.14722/eurousec.2017.23007
- 发表时间:2017
- 期刊:
- 影响因子:0
- 作者:Becker I
- 通讯作者:Becker I
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Martina Angela Sasse其他文献
Studying users’ adaptation to Android’s run-time fine-grained access control system
- DOI:
10.1016/j.jisa.2018.02.004 - 发表时间:
2018-06-01 - 期刊:
- 影响因子:
- 作者:
Panagiotis Andriotis;Gianluca Stringhini;Martina Angela Sasse - 通讯作者:
Martina Angela Sasse
Martina Angela Sasse的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Martina Angela Sasse', 18)}}的其他基金
Easy Expression of Authorisation Policies
授权策略轻松表达
- 批准号:
EP/D052424/1 - 财政年份:2006
- 资助金额:
$ 148.86万 - 项目类别:
Research Grant
相似海外基金
CAREER: Improving the Lifecycle Security of Microcontroller Devices
职业:提高微控制器设备的生命周期安全性
- 批准号:
2238264 - 财政年份:2023
- 资助金额:
$ 148.86万 - 项目类别:
Continuing Grant
An innovative platform to reduce the risk of cyber attacks on smart contracts for all blockchains by minimising human effort and improving the efficacy of security testing.
一个创新平台,通过最大限度地减少人力并提高安全测试的效率,降低所有区块链智能合约遭受网络攻击的风险。
- 批准号:
10047308 - 财政年份:2023
- 资助金额:
$ 148.86万 - 项目类别:
Collaborative R&D
CHAI: Improving the Resiliency and Security of the Cyber-Infrastructure at SWC
CHAI:提高 SWC 网络基础设施的弹性和安全性
- 批准号:
2231858 - 财政年份:2022
- 资助金额:
$ 148.86万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Corporeal Cybersecurity: Improving End-User Security and Privacy with Physicalized Computing Interface
SaTC:核心:小型:实体网络安全:通过物理化计算接口提高最终用户安全和隐私
- 批准号:
2316294 - 财政年份:2022
- 资助金额:
$ 148.86万 - 项目类别:
Standard Grant
Improving and Scaling Security Operations Automation and Orchestration using Predictive Machine Learning
使用预测机器学习改进和扩展安全运营自动化和编排
- 批准号:
580634-2022 - 财政年份:2022
- 资助金额:
$ 148.86万 - 项目类别:
Alliance Grants
Improving Cognitive and Collaborative Support for Security Threat Hunters
改善对安全威胁猎人的认知和协作支持
- 批准号:
571669-2021 - 财政年份:2022
- 资助金额:
$ 148.86万 - 项目类别:
Alliance Grants
Physical Layer Design for Improving Throughput and Security in Wireless Networks
用于提高无线网络吞吐量和安全性的物理层设计
- 批准号:
RGPIN-2020-05984 - 财政年份:2022
- 资助金额:
$ 148.86万 - 项目类别:
Discovery Grants Program - Individual
Improving network security and user authentication
提高网络安全和用户身份验证
- 批准号:
580510-2022 - 财政年份:2022
- 资助金额:
$ 148.86万 - 项目类别:
University Undergraduate Student Research Awards
Physical Layer Design for Improving Throughput and Security in Wireless Networks
用于提高无线网络吞吐量和安全性的物理层设计
- 批准号:
DGDND-2020-05984 - 财政年份:2022
- 资助金额:
$ 148.86万 - 项目类别:
DND/NSERC Discovery Grant Supplement
Excellence in Research: Improving the Integrity and Security of Integrated Circuits Through Effective Detection of Malicious Alterations
卓越的研究:通过有效检测恶意篡改提高集成电路的完整性和安全性
- 批准号:
2200681 - 财政年份:2022
- 资助金额:
$ 148.86万 - 项目类别:
Standard Grant