A qualitative study of users' view on information security

被引:173
作者
Albrechtsen, Eirik [1 ]
机构
[1] Norwegian Univ Sci & Technol, Dept Ind Econ & Technol Management, N-7491 Trondheim, Norway
关键词
information security; information security management; users; awareness; behaviour; participation; qualitative research;
D O I
10.1016/j.cose.2006.11.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Users play an important role in the information security performance of organisations by their security awareness and cautious behaviour. Interviews of users at an IT-company and a bank were qualitatively analyzed in order to explore users' experience of information security and their personal role in the information security work. The main patterns of the study were: (1) users state to be motivated for information security work, but do not perform many individual security actions; (2) high information security workload creates a conflict of interest between functionality and information security; and (3) documented requirements of expected information security behaviour and general awareness campaigns have little effect alone on user behaviour and awareness. The users consider a user-involving approach to be much more effective for influencing user awareness and behaviour. (c) 2006 Elsevier Ltd. All rights reserved.
引用
收藏
页码:276 / 289
页数:14
相关论文
共 43 条
[1]  
AARO LA, 1996, MENNESKELIGE FAKTOR
[2]   Users are not the enemy [J].
Adams, A ;
Sasse, MA .
COMMUNICATIONS OF THE ACM, 1999, 42 (12) :41-46
[3]  
ALBRECHTSEN E, 2004, FLIS FINGEREN RAGNAR, P319
[4]  
[Anonymous], 1991, RISK RATIONALITY
[5]  
[Anonymous], COMMUNICATING RISKS
[6]  
[Anonymous], KVALITATIVE METODER
[7]  
[Anonymous], USABILITY TURNING TE
[8]  
Argyris C, 1996, ORG LEARNING
[9]  
Beck Ulrich., 1992, Risk society: Towards a new modernity
[10]   Computer security impaired by legitimate users [J].
Besnard, D ;
Arief, B .
COMPUTERS & SECURITY, 2004, 23 (03) :253-264