Human Factors and Information Security
Lewis Hassell, Susan Wiedenbeck
Abstract
Lewis Hassell, Susan Wiedenbeck
Abstract
Security, including information systems security, is a societal problem, not just a technology problem. Getting people to adopt secure IS practices requires more than traditional ease of use studies and user requirements analysis. It requires users of advanced information systems to adopt a culture of security. We propose a model of organizational security, which includes user security behavior as a key element. Next, we propose a model of user security behavior itself, and discuss how it shows how we have to create this culture of security. Lastly, we discuss directions for future research.
OpenAlex reports 13 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Security, including information systems security, is a societal problem, not just a technology problem. Getting people to adopt secure IS practices requires more than traditional ease of use studies and user requirements analysis. It requires users of advanced information systems to adopt a culture of security. We propose a model of organizational security, which includes user security behavior as a key element. Next, we propose a model of user security behavior itself, and discuss how it shows how we have to create this culture of security. Lastly, we discuss directions for future research.
Key concepts: Security information and event management, Human-computer interaction in information security, Computer security model, Security through obscurity, Computer security, Cloud computing security, Computer science, Information security