首页> 外文会议>Hawaii International Conference on System Sciences >Can Relaxing Security Policy Restrictiveness Improve User Behavior? A Field Study of Authentication Credential Usage
【24h】

Can Relaxing Security Policy Restrictiveness Improve User Behavior? A Field Study of Authentication Credential Usage

机译:放宽安全策略限制可以改善用户行为吗?身份验证凭据使用的现场研究

获取原文

摘要

Often, security policies take an overly proscriptive approach designed to shape 'secure' behavior in the specification of constraints, controls, and impediments to free action. In the case of very detailed policies, the user may not even understand the logic behind the behavior. This research poses a simple premise: if a desired state of system security can be achieved with a policy that affords the user a range of behavioral options, would the user be more likely to comply with the policy? We present findings from a field experiment in the context of password selection where secure behavior was enhanced by relaxing proscription (and prescription) by allowing universal cues in additional feedback tools to take precedence over explicit behavioral requirements. This is in keeping with aspects of Activity Theory which proposes that familiar tools influence actor-structure interactions that lead to desired outcomes.
机译:安全策略通常会采用过分规范的方法,旨在在约束,控制和自由行动的障碍规范中塑造“安全”行为。对于非常详细的策略,用户甚至可能不了解行为背后的逻辑。这项研究提出了一个简单的前提:如果可以通过向用户提供一系列行为选择的策略来实现所需的系统安全状态,那么用户是否更有可能遵守该策略?我们在密码选择的背景下提供了来自现场实验的发现,其中通过允许其他反馈工具中的通用提示优先于明确的行为要求,通过放宽禁令(和处方)来增强安全行为。这与活动理论的各个方面保持一致,活动理论提出了熟悉的工具会影响导致预期结果的行为者与结构的相互作用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号