Nudge to Promote Employees' Information Security Compliance Behavior: A Field Study

被引:0
|
作者
Inaba, Midori [1 ]
Terada, Takeaki [2 ,3 ]
机构
[1] Inst Informat Secur, Yokohama, Kanagawa, Japan
[2] Fujitsu Ltd, Kawasaki, Kanagawa, Japan
[3] Nagasaki Univ, Nagasaki, Japan
关键词
nudge; security behavior; information security policy; compliance; security patch application; POLICY COMPLIANCE; IMPACT; ORGANIZATIONS; DETERRENCE;
D O I
10.1109/CSR57506.2023.10224994
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This field study performed an experiment to observe practical effects of a nudge on facilitating employees' security compliance in one company's department. We examined if the nudges speeded up the employees' manual implication of applying the security patch to all their devices, which constituted a security compliance behavior in the experimental environment. Each employee was provided with one of three types of nudges informing the state of others: informing about the progress of general employees with a similar number of devices, informing about the progress of one's working team members, and providing information regarding both. As a result, providing information regarding both uniformly accelerated their patching behaviors although providing only team information severely delayed these behaviors. This study indicates the potential of a nudge as a security management intervention and showcases its effective design.
引用
收藏
页码:335 / 340
页数:6
相关论文
共 50 条
  • [1] Readability as lever for employees' compliance with information security policies
    Ammann, Franz-Emst
    Sowa, Aleksandra
    ISACA Journal, 2013, 4 : 39 - 42
  • [2] Leader power and employees' information security policy compliance
    Kim, Hyungjin Lukas
    Choi, HanByeol Stella
    Han, Jinyoung
    SECURITY JOURNAL, 2019, 32 (04) : 391 - 409
  • [3] Leader power and employees’ information security policy compliance
    Hyungjin Lukas Kim
    HanByeol Stella Choi
    Jinyoung Han
    Security Journal, 2019, 32 : 391 - 409
  • [4] Employees' adherence to information security policies: An exploratory field study
    Siponen, Mikko
    Mahmood, M. Adam
    Pahnila, Seppo
    INFORMATION & MANAGEMENT, 2014, 51 (02) : 217 - 224
  • [5] Employees' information security policy compliance: A norm activation perspective
    Yazdanmehr, Adel
    Wang, Jingguo
    DECISION SUPPORT SYSTEMS, 2016, 92 : 36 - 46
  • [6] Information Security Policies Compliance among Employees in Cybersecurity Malaysia
    Kadir, Mohd Razilan Abdul
    Norman, Sharifah Norwahidah Syed
    Rahman, Safawi Abdul
    Ahmad, Abdul Rahman
    Bunawan, Ap-Azli
    VISION 2020: INNOVATION MANAGEMENT, DEVELOPMENT SUSTAINABILITY, AND COMPETITIVE ECONOMIC GROWTH, 2016, VOLS I - VII, 2016, : 2419 - 2430
  • [7] The effect of perceived organizational culture on employees' information security compliance
    Karlsson, Martin
    Karlsson, Fredrik
    Astrom, Joachim
    Denk, Thomas
    INFORMATION AND COMPUTER SECURITY, 2022, 30 (03) : 382 - 401
  • [8] Improving employees' compliance through information systems security training: An action research study
    Puhakainen P.
    Siponen M.
    MIS Quarterly: Management Information Systems, 2010, 34 (04): : 757 - 778
  • [9] IMPROVING EMPLOYEES' COMPLIANCE THROUGH INFORMATION SYSTEMS SECURITY TRAINING: AN ACTION RESEARCH STUDY
    Puhakainen, Petri
    Siponen, Mikko
    MIS QUARTERLY, 2010, 34 (04) : 757 - 778
  • [10] Security Awareness: The First Step in Information Security Compliance Behavior
    Hwang, Inho
    Wakefield, Robin
    Kim, Sanghyun
    Kim, Taeha
    JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2021, 61 (04) : 345 - 356