首页> 外文期刊>Computers & Security >Analyzing the role of cognitive and cultural biases in the internalization of information security policies: Recommendations for information security awareness programs
【24h】

Analyzing the role of cognitive and cultural biases in the internalization of information security policies: Recommendations for information security awareness programs

机译:分析认知和文化偏见在信息安全政策内部化中的作用:有关信息安全意识计划的建议

获取原文
获取原文并翻译 | 示例

摘要

Standards and best practices for information security awareness programs focus on the content and processes of the programs, without taking into consideration how individuals internalize security-related information and how individuals make security related decisions. Relevant literature, however has identified that individual perceptions, beliefs, and biases significantly influence security policy compliance behavior. Security awareness programs need, therefore, to be aligned with the factors affecting the internalization of the communicated security objectives. This paper explores the role of cognitive and cultural biases in shaping information security perceptions and behaviors. We draw upon related literature from contiguous disciplines (namely behavioral economics and health and safety research) to develop a conceptual framework and analyze the role of cognitive and cultural biases in information security behavior. We discuss the implications of biases for security awareness programs and provide a set of recommendations for planning and implementing awareness programs, and for designing the related material. This paper opens new avenues for information security awareness research with regard to security decision making and proposes practical recommendations for planning and delivering security awareness programs, so as to exploit and alleviate the effect of cognitive and cultural biases on shaping risk perceptions and security behavior.
机译:信息安全意识计划的标准和最佳实践侧重于计划的内容和流程,而不考虑个人如何内部化与安全相关的信息以及个人如何做出与安全相关的决策。但是,相关文献已经确定,个人的看法,信念和偏见会严重影响安全策略的遵从行为。因此,安全意识计划需要与影响所传达的安全目标内部化的因素保持一致。本文探讨了认知和文化偏见在塑造信息安全认知和行为中的作用。我们从连续学科(即行为经济学和健康与安全研究)中借鉴相关文献,以建立概念框架并分析认知和文化偏见在信息安全行为中的作用。我们讨论了偏见对安全意识计划的影响,并为规划和实施意识计划以及设计相关材料提供了一组建议。本文为有关安全决策的信息安全意识研究开辟了新途径,并提出了规划和实施安全意识计划的实用建议,以便利用和减轻认知和文化偏见对塑造风险感知和安全行为的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号