首页> 外文会议>Financial cryptography and data security >'Comply or Die' Is Dead: Long Live Security-Aware Principal Agents
【24h】

'Comply or Die' Is Dead: Long Live Security-Aware Principal Agents

机译:“遵从或死”已死:具备安全保护意识的主要代理商

获取原文
获取原文并翻译 | 示例

摘要

Information security has adapted to the modern collaborative organisational nature, and abandoned "command-and-control" approaches of the past. But when it comes to managing employee's information security behaviour, many organisations still use policies proscribing behaviour and sanctioning non-compliance. Whilst many organisations are aware that this "comply or die" approach does not work for modern enterprises where employees collaborate, share, and show initiative, they do not have an alternative approach to fostering secure behaviour. We present an interview analysis of 126 employees' reasons for not complying with organisational policies, identifying the perceived conflict of security with productive activities as the key driver for non-compliance and confirm the results using a survey of 1256 employees. We conclude that effective problem detection and security measure adaptation needs to be de-centralised - employees are the principal agents who must decide how to implement security in specific contexts. But this requires a higher level of security awareness and skills than most employees currently have. Any campaign aimed at security behaviour needs to transform employee's perception of their role in security, transforming them to security-aware principal agents.
机译:信息安全已经适应了现代协作组织的本质,并且放弃了过去的“命令与控制”方法。但是,在管理员工的信息安全行为方面,许多组织仍然使用政策来规定行为和制裁违规行为。尽管许多组织意识到,这种“遵守或死亡”方法不适用于员工进行协作,共享和展示主动性的现代企业,但他们没有替代的方法来促进安全行为。我们对126名员工不遵守组织政策的原因进行了访谈分析,确定了生产活动导致的安全冲突是不遵守情事的主要原因,并通过对1256名员工的调查来确认结果。我们得出的结论是,有效的问题检测和安全措施适应性需要下放权力-员工是主要代理商,他们必须决定如何在特定情况下实施安全性。但这需要比当前大多数员工更高的安全意识和技能。任何针对安全行为的运动都需要转变员工对其在安全角色中的作用的认识,并将其转变为具有安全意识的委托人。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号