Chief Information Security Officers (CISOs) put increasing focus on employees, either as a valuable security asset, or as a danger. Recent studies indicated that CISOs do not take employees' troubles with security policies into account. They seem to lack awareness of how policies would need to be adapted to different groups of employees within the organization. We investigate intersections and differences between organizational challenges, needs, wishes, and ideas of CISOs and one (micro-)group of employees-apprentices-based on personas. We re-analyzed qualitative data gathered from 8 workshops with 30 CISOs and a workshop with 17 apprentices to derive personas for both groups that help to identify where CISOs' and employees' incentives diverge in terms of security. The persona approach was chosen here to reduce the complexity of the interrelationships and to make the respective perspectives more tangible in a structured and visualized way. We find diverging ideas both within the persona groups as well as between the CISOs and the apprentices about successful security communication and dealing with errors. We propose ways to converge those positions, such as the integration of Organizational Behavior Management (OBM) and user-friendly reporting systems. © 2024 IEEE.
Author Keywords
Index Keywords