Nudge to Promote Employees' Information Security Compliance Behavior: A Field Study

被引:0
|
作者
Inaba, Midori [1 ]
Terada, Takeaki [2 ,3 ]
机构
[1] Inst Informat Secur, Yokohama, Kanagawa, Japan
[2] Fujitsu Ltd, Kawasaki, Kanagawa, Japan
[3] Nagasaki Univ, Nagasaki, Japan
关键词
nudge; security behavior; information security policy; compliance; security patch application; POLICY COMPLIANCE; IMPACT; ORGANIZATIONS; DETERRENCE;
D O I
10.1109/CSR57506.2023.10224994
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This field study performed an experiment to observe practical effects of a nudge on facilitating employees' security compliance in one company's department. We examined if the nudges speeded up the employees' manual implication of applying the security patch to all their devices, which constituted a security compliance behavior in the experimental environment. Each employee was provided with one of three types of nudges informing the state of others: informing about the progress of general employees with a similar number of devices, informing about the progress of one's working team members, and providing information regarding both. As a result, providing information regarding both uniformly accelerated their patching behaviors although providing only team information severely delayed these behaviors. This study indicates the potential of a nudge as a security management intervention and showcases its effective design.
引用
收藏
页码:335 / 340
页数:6
相关论文
共 50 条
  • [41] The sufficiency of the theory of planned behavior for explaining information security policy compliance
    Sommestad, Teodor
    Karlzen, Henrik
    Hallberg, Jonas
    INFORMATION AND COMPUTER SECURITY, 2015, 23 (02) : 200 - 217
  • [42] Information Security Policy Compliance: The Role of Information Security Awareness
    AL-Omari, Ahmad
    El-Gayar, Omar
    Deokar, Amit
    AMCIS 2012 PROCEEDINGS, 2012,
  • [43] Nudge to Health: Harnessing Decision Research to Promote Health Behavior
    Li, Meng
    Chapman, Gretchen B.
    SOCIAL AND PERSONALITY PSYCHOLOGY COMPASS, 2013, 7 (03): : 187 - 198
  • [44] Evolvement of Information Security Research on Employees Behavior: A Systematic Review and Future Direction
    Alaskar, Mohamed
    Vodanovich, Shahper
    Shen, Kathy Ning
    2015 48TH HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES (HICSS), 2015, : 4241 - 4250
  • [45] Information Security Behavior: A Cross-Cultural Comparison of Irish and US Employees
    Connolly, Lena Y.
    Lang, Michael
    Wall, David S.
    INFORMATION SYSTEMS MANAGEMENT, 2019, 36 (04) : 306 - 322
  • [46] Employees' BYOD Security Policy Compliance in the Public Sector
    Palanisamy, Rathika
    Norman, Azah Anir
    Kiah, Miss Laiha Mat
    JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2024, 64 (01) : 62 - 77
  • [47] Information security policy compliance: a higher education case study
    Alshare, Khaled A.
    Lane, Peggy L.
    Lane, Michael R.
    INFORMATION AND COMPUTER SECURITY, 2018, 26 (01) : 91 - 108
  • [48] A typology of employees' information security behaviour
    Ahmad, Zauwiyah
    Norhashim, Mariati
    Song, Ong Thian
    Hui, Liew Tze
    2016 4TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY (ICOICT), 2016,
  • [49] INFORMATION SECURITY POLICY COMPLIANCE: AN EMPIRICAL STUDY OF RATIONALITY-BASED BELIEFS AND INFORMATION SECURITY AWARENESS
    Bulgurcu, Burcu
    Cavusoglu, Hasan
    Benbasat, Izak
    MIS QUARTERLY, 2010, 34 (03) : 523 - 548
  • [50] Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness
    Bulgurcu B.
    Cavusoglu H.
    Benbasat I.
    MIS Quarterly: Management Information Systems, 2010, 34 (SPEC. ISSUE 3): : 523 - 548