Iacovos Kirlappos, Adam Beautement and M. Angela Sasse
Information security has adapted to the modern collaborative organisational nature, and abandoned “command-and-control” approaches of the past. But when it comes to managing employee’s information security behaviour, many organisations still use policies proscribing behaviour and sanctioning non-compliance. Whilst many organisations are aware that this “comply or die” approach does not work for modern enterprises where employees collaborate, share, and show initiative, they do not have an alternative approach to fostering secure behaviour. We present an interview analysis of 126 employees’ reasons for not complying with organisational policies, identifying the perceived conflict of security with productive activities as the key driver for non-compliance and confirm the results using a survey of 1256 employees. We conclude that effective problem detection and security measure adaptation needs to be de-centralised – employees are the principal agents who must decide how to implement security in specific contexts. But this requires a higher level of security awareness and skills than most employees currently have. Any campaign aimed at security behaviour needs to transform employee’s perception of their role in security, transforming them to security-aware principal agents.
Date: April 1, 2013 Presented: Financial Cryptography 2013 Workshop on Usable Security (USEC ‘13), Okinawa, Japan, 01 Apr 2013 – 05 Oct 2013 Published: Lecture Notes in Computer Science Volume 7862, 2013, pp 70-82. Publisher URL: http://link.springer.com/chapter/10.1007%2F978-3-642-41320-9_5 Full Text: http://discovery.ucl.ac.uk/1419506/