There is a conflict between the need for security compliance by users and the fact that commonly they cannot afford to dedicate much of their time and energy to that security. A balanced level of user engagement in security is difficult to achieve due to difference of priorities between the business perspective and the security perspective. We sought to find a way to engage users minimally, yet efficiently, so that they would both improve their security awareness and provide necessary feedback for improvement purposes to security designers. We have developed a persuasive software toolkit to engage users in structured discussions about security vulnerabilities in their company and potential interventions addressing these. In the toolkit we have adapted and integrated an established framework from conventional crime prevention. In the research reported here we examine how non-professionals perceived security problems through a short-term use of the toolkit. We present perceptions from a pilot lab study in which randomly recruited participants had to analyze a crafted insider threat problem using the toolkit. Results demonstrate that study participants were able to successfully identify causes, propose interventions and engage in providing feedback on proposed interventions. Subsequent interviews show that participants have developed greater awareness of information security issues and the framework to address these, which in a real setting would lead ultimately to significant benefits for the organization. These results indicate that when well-structured such short-term engagement is sufficient for users to meaningfully take part in complex security discussions and develop in-depth understanding of theoretical principles of security.
翻译:一方面,用户需要遵守安全规定,另一方面,他们通常负担不起将大部分时间和精力用于安全,两者之间存在冲突。由于业务观点和安全观点之间的优先事项不同,因此难以实现均衡的用户参与安全的程度。我们设法找到一种办法,使用户以最低、但效率低的方式参与,以便他们既能提高安全意识,又能向安全设计者提供必要的反馈,从而改进安全设计者。我们开发了一个有说服力的软件工具包,让用户参与有关其公司安全脆弱性的分阶段讨论,以及解决这些问题的潜在干预措施。在工具包中,我们调整并整合了常规预防犯罪的既定框架。在本次报告的研究中,我们研究了非专业人员如何通过短期使用工具包来看待安全问题。我们从试验性实验室研究中提出一些看法,随机征聘的参与者不得不利用工具包分析精心策划的内部威胁问题。结果显示,研究参与者能够成功地查明原因,提出干预措施,并参与就拟议干预措施提供反馈。随后的访谈表明,参与者对信息安全问题和解决这些问题的框架有了更多的了解,在实际情况下,将最终导致对安全进行重大深度讨论,从而在组织中充分理解。这些结果表明,在安全结构上对用户来说,这些都具有重大意义。