Information Security and Practice: The User's Perspective

被引:0
|
作者
Clarke, Nathan [1 ,4 ]
Li, Fudong [1 ]
Furnell, Steven [1 ,4 ]
Stengel, Ingo [2 ]
Ganis, Giorgio [3 ]
机构
[1] Univ Plymouth, Ctr Secur Commun & Network Res, Plymouth PL4 8AA, Devon, England
[2] Univ Appl Sci Karlsruhe, Karlsruhe, Germany
[3] Univ Plymouth, Fac Hlth & Human Sci, Plymouth PL4 8AA, Devon, England
[4] Edith Cowan Univ, Secur Res Inst, Churchlands, WA 6018, Australia
关键词
end-user; IT security; survey; AUTHENTICATION; ATTITUDES;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The use of Information Technology (IT) has become common practice in our everyday lives both for business and private purposes. While people enjoy the convenience that IT offers, it also poses various security threats if not used properly, including malware, hacking, and information disclosure. Unfortunately, the scale and consequence of cyber threats has increased significantly year-on-year despite various security controls having been developed and deployed. It is evident that end users play a significant role within the information security domain, as they are frequently the primary target and the main force behind incidents. Nonetheless, whilst there are annual security surveys for organisations, less effort were given regarding assessing how individuals practice information security by the research community. Therefore, this paper presents a survey that investigates user's IT security practice and behaviour. In total, 400 respondents were surveyed during a five month period (i.e. November 2014 - March 2015). Overall, the results demonstrate that end users practice better IT security than typically thought although it appears only at a relatively basic level. For example, whilst a reasonably good proportion of participants (66%) claimed that they never share their passwords with others, 76% have used the same password on multiple sensitive accounts. Almost three quarters (72%) of responders never click on links or attachments within emails from unknown sources, but this is significantly reduced (to 36%) when someone they knew sent the email. Two-thirds of users (65%) do appreciate the importance of antivirus software as they always keep their antivirus software updated; however, less care is given to other applications/systems as only 44% would do the same and more alarmingly 65% even cancel or delay the security update process. Over two thirds (68%) of participants do not always backup their data, and only half of the participants (53%) claimed that they always destroy their data before hardware disposal. The results of the survey suggest that whilst levels of awareness are improving, there is still a significant gap between existing and required levels of information security knowledge and practice. Arguably, users are currently being overwhelmed by the burden being placed upon them to remain secure. The range of technologies they use (60% using more than 3 devices), the widespread use of online services (89% using at least 5 IT services) highlight users are becoming or have become technology dependent but perhaps without being security savvy.
引用
收藏
页码:81 / 89
页数:9
相关论文
共 50 条
  • [1] USER PERCEPTIONS OF INFORMATION SECURITY: A MULTINATIONAL PERSPECTIVE
    Cheskiewicz, S.
    Colobran, M.
    [J]. ICERI2016: 9TH INTERNATIONAL CONFERENCE OF EDUCATION, RESEARCH AND INNOVATION, 2016, : 4257 - 4257
  • [2] USER'S PERSPECTIVE: INFORMATION RETRIEVAL AND USABILITY
    Zambrano Silva, Salvador
    Villanueva Pla, Enrique
    Rus Molina, Lola
    [J]. ANALES DE DOCUMENTACION, 2007, 10 : 451 - 483
  • [3] Revisiting information security risk management challenges: a practice perspective
    Bergstrom, Erik
    Lundgren, Martin
    Ericson, Asa
    [J]. INFORMATION AND COMPUTER SECURITY, 2019, 27 (03) : 358 - 372
  • [4] Climate information for food security: Responding to user's climate information needs
    Waiswa, M.
    Mulamba, P.
    Isabirye, P.
    [J]. Climate Prediction and Agriculture: Advances and Challenges, 2007, : 225 - 248
  • [5] User participation in information security
    Albrechtsen, E.
    Hovden, J.
    [J]. RISK, RELIABILITY AND SOCIETAL SAFETY, VOLS 1-3: VOL 1: SPECIALISATION TOPICS; VOL 2: THEMATIC TOPICS; VOL 3: APPLICATIONS TOPICS, 2007, : 2551 - +
  • [6] Changing information needs: One end user's perspective
    Borchardt, JK
    [J]. ABSTRACTS OF PAPERS OF THE AMERICAN CHEMICAL SOCIETY, 1996, 212 : 38 - CINF
  • [7] Economic perspective of information security
    Zhu, G
    Dai, J
    [J]. SAM'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND MANAGEMENT, VOLS 1 AND 2, 2003, : 527 - 533
  • [8] Appraisal on User's Comprehension in Security Warning Dialogs: Browsers Usability Perspective
    Yi, Christine Lim Xin
    Zaaba, Zarul Fitri
    Aminuddin, Mohamad Amar Irsyad Mohd
    [J]. ADVANCES IN CYBER SECURITY (ACES 2019), 2020, 1132 : 320 - 334
  • [9] Information Security Theory and Practice
    Vinaja, Robert
    [J]. JOURNAL OF GLOBAL INFORMATION TECHNOLOGY MANAGEMENT, 2015, 18 (04) : 316 - 318
  • [10] Unraveling juxtaposed effects of biometric characteristics on user security behaviors: A controversial information technology perspective
    Zhang, Jing
    Liu, Zilong
    Luo, Xin
    [J]. DECISION SUPPORT SYSTEMS, 2024, 183