2011•Journal of the Association for Information SystemsRequires access

Controlling insider threats with information security policies.

Ali Alper Yayla

Open publisher page 14 citations

Abstract

Over the past decade, several studies, industry reports and surveys have revealed that insider threats constitute a significant role in information security. Following the literature, we categorized insider threats as intentional and unintentional. Computer misuse and fraud are considered as the two most common intentional threats, whereas, user errors and negligence are considered as the two most common unintentional threats. Building on the organizational behavior, psychology and criminology literatures, in this paper, we introduce different socio-behavioral control mechanisms to mitigate insider threats to information security. These mechanisms include employees’ integration and commitment to their job and organization, deterrence measures, management of work related stress, awareness of security issues, and motivation of employees. These socio-behavioral mechanisms are also accompanied by technical aspects such as user interface of security tools and technology-based controls. Lastly, the integrative and reinforcing role of security policies within the proposed framework is discussed.

About this research paper

What this paper is about

Over the past decade, several studies, industry reports and surveys have revealed that insider threats constitute a significant role in information security. Following the literature, we categorized insider threats as intentional and unintentional. Computer misuse and fraud are considered as the two most common intentional threats, whereas, user errors and negligence are considered as the two most common unintentional threats. Building on the organizational behavior, psychology and criminology literatures, in this paper, we introduce different socio-behavioral control mechanisms to mitigate insider threats to information security. These mechanisms include employees’ integration and commitment to their job and organization, deterrence measures, management of work related stress, awareness of security issues, and motivation of employees. These socio-behavioral mechanisms are also accompanied by technical aspects such as user interface of security tools and technology-based controls. Lastly, the integrative and reinforcing role of security policies within the proposed framework is discussed.

Why it matters

OpenAlex reports 14 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Over the past decade, several studies, industry reports and surveys have revealed that insider threats constitute a significant role in information security. Following the literature, we categorized insider threats as intentional and unintentional. Computer misuse and fraud are considered as the two most common intentional threats, whereas, user errors and negligence are considered as the two most common unintentional threats. Building on the organizational behavior, psychology and criminology literatures, in this paper, we introduce different socio-behavioral control mechanisms to mitigate insider threats to information security. These mechanisms include employees’ integration and commitment to their job and organization, deterrence measures, management of work related stress, awareness of security issues, and motivation of employees. These socio-behavioral mechanisms are also accompanied by technical aspects such as user interface of security tools and technology-based controls. Lastly, the integrative and reinforcing role of security policies within the proposed framework is discussed.

Key concepts: Insider threat, Insider, Information security, Computer security, Information security management, Security management, Deterrence theory, Security controls

Related papers

Back to paper searchBrowse research topicsOriginal source
Controlling insider threats with information security policies. — Research Paper | ScholarLens