课题基金 / 基金详情

Supporting Security Policy with Effective Digital Intervention (SSPEDI)

Supporting Security Policy with Effective Digital Intervention (SSPEDI)
通过有效的数字干预支持安全策略 (SSPEDI)
批准号:
EP/P011829/1
负责人:
Matthew Collinson
金额:
$96.41万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2017
资助国家:
英国
项目状态:
已结题
起止时间:
2017 至 --

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
The behaviour of people is known to be critical to the security of organizations across all sectors of the economy. As users of IT systems, their action, or inaction, can create cyber security vulnerabilities. For example, users can be tempted to give away their authentication credentials (by phishing), to install malign software (malware), choose weak or inadequate passwords, or they may fail to install security patches, to scan computers for viruses, or to make secure backups of critical data. Organizations design security policies which users are supposed to follow, for example, instructing them not to give away their authentication (login) credentials, or not to open certain kinds of attachments sent in unsolicited emails. However, in practice, managers find it very difficult to encourage users to follow policy. This project will investigate effective ways to improve security communications with users, to enable them to understand security risks, and to persuade them to comply with policy. Our hypothesis is that to be most effective, communications and policy implementations must take into account individual personalities and motivations. Technological support is therefore required to support security communications and security persuasion so that it can scale up to large organizations. We propose to transfer ideas and knowledge from the existing academic field of persuasive technologies and digital behaviour interventions, and apply them to the user security compliance problem. We will build, and trial, real technologies that implement persuasive strategies in real user security scenarios. These scenarios will be selected in partnership with industrial security practitioners. The project takes a broad, interdisciplinary view of the roots of the user compliance challenge, and draws additionally on expert knowledge from the fields of psychology, behavioural decision, security, sentiment analysis and argumentation in search of solutions.
期刊论文(8)
专著(0)
科研奖励(0)
会议论文
DOI: --
发表时间: 2021
期刊:
影响因子: --
作者: [Al-Hadhrami N]
通讯作者: Al-Hadhrami N
DOI: 10.1007/978-3-319-59569-6_38
发表时间: 2017-06
期刊:
影响因子: --
作者: [M. Barawi;Chenghua Lin;Advaith Siddharthan]
通讯作者: M. Barawi;Chenghua Lin;Advaith Siddharthan
Tell Me How to Survey: Literature Review Made Simple with Automatic Reading Path Generation
告诉我如何调查:通过自动生成阅读路径使文献综述变得简单
DOI: 10.48550/arxiv.2110.06354
发表时间: 2021
期刊:
影响因子: --
作者: [Ding J]
通讯作者: Ding J
How can persuasion reduce user cyber security vulnerabilities?
如何说服减少用户网络安全漏洞?
DOI: --
发表时间: 2018
期刊:
影响因子: --
作者: [John Paul Vargheese]
通讯作者: John Paul Vargheese
6
    海外基金