Fixing Security Together: Leveraging trust relationships to improve security in organizations

Fixing Security Together: Leveraging trust relationships to improve security in organizations
复制标题

共同修复安全性:利用信任关系提高组织的安全性

DOI:
--
复制
发表时间:
2015
期刊:
影响因子:
--
通讯作者:
M. Sasse
M. Sasse
中科院分区:
--
文献类型:
--
作者:
I. Kirlappos;M. Sasse

文献摘要

被引文献

相似文献

当前的信息安全方法侧重于部署安全机制、制定政策并将其传达给员工。很少考虑政策和机制如何影响组织中的信任关系,进而影响安全行为。我们对两家大型跨国组织的208名员工进行了深入访谈分析,发现了两种信任关系:组织与其员工之间的信任(组织 - 员工信任)以及员工之间的信任(员工间信任)。当安全措施干扰员工完成工作任务的能力时,他们依靠员工间信任来克服这些障碍(例如,与被系统锁定且急需访问权限的同事共享密码)。因此,违规行为是一种协作行为,这进一步增进了员工间的信任,因为员工现在成了“共犯”。这两种关系的存在也使员工面临一个明显的困境:要么努力遵守繁琐的安全规定(维护组织 - 员工信任),要么通过违反安全规定来帮助同事(维护员工间信任)。我们得出结论,安全政策和机制的设计者需要支持这两种类型的信任,并讨论如何利用信任来实现有效的安全保护。这可以加强组织合作以应对安全挑战,激励员工安全行事,同时也减少对昂贵的物理和技术安全机制的需求。
Current approaches to information security focused on deploying security mechanisms, creating policies and communicating those to employees. Little consideration was given to how policies and mechanisms affect trust relationships in an organization, and in turn security behavior. Our analysis of 208 in-depth interviews with employees in two large multinational organizations found two trust relationships: between the organization and its employees (organization-employee trust), and between employees (inter-employee trust). When security interferes with employees’ ability to complete work tasks, they rely on inter-employee trust to overcome those obstacles (e.g. sharing a password with a colleague who is locked out of a system and urgently needs access). Thus, non-compliance is a collaborative action, which develops inter-employee trust further, as employees now become “partners in crime”. The existence of these two relationships also presents employees with a clear dilemma: either try to comply with cumbersome security (and honor organization-employee trust) or help their colleagues by violating security (preserving inter-employee trust). We conclude that designers of security policies and mechanisms need to support both types of trust, and discuss how to leverage trust to achieve effective security protection. This can enhance organizational cooperation to tackle security challenges, provide motivation for employees to behave securely, while also reducing the need for expensive physical and technical security mechanisms