Conference paper 2024

Contrasting and Synergizing CISOs' and Employees' Attitudes, Needs, and Resources for Security Using Personas

Proceedings - 9th IEEE European Symposium on Security and Privacy Workshops, Euro S and PW 2024
Conference · pp. 456-472
Abstract

Chief Information Security Officers (CISOs) put increasing focus on employees, either as a valuable security asset, or as a danger. Recent studies indicated that CISOs do not take employees' troubles with security policies into account. They seem to lack awareness of how policies would need to be adapted to different groups of employees within the organization. We investigate intersections and differences between organizational challenges, needs, wishes, and ideas of CISOs and one (micro-)group of employees-apprentices-based on personas. We re-analyzed qualitative data gathered from 8 workshops with 30 CISOs and a workshop with 17 apprentices to derive personas for both groups that help to identify where CISOs' and employees' incentives diverge in terms of security. The persona approach was chosen here to reduce the complexity of the interrelationships and to make the respective perspectives more tangible in a structured and visualized way. We find diverging ideas both within the persona groups as well as between the CISOs and the apprentices about successful security communication and dealing with errors. We propose ways to converge those positions, such as the integration of Organizational Behavior Management (OBM) and user-friendly reporting systems. © 2024 IEEE.

Keywords

Author Keywords

Apprentices Chief Information Security Officer Human-Centred Security Organizational Behavior Management Personas User-friendly Reporting Systems

Index Keywords

Information management Apprentices User friendly Behavior management Chief information security officers Employee attitudes Human-centered security Organizational behavior Organizational behavior management Persona Reporting systems User-friendly reporting system
Author Affiliations
Ruhr-Universitat Bochum, Bochum, Nordrhein-Westfalen, Germany
Funding & Acknowledgements
No funding information
References 10 References
1 Beris, Odette, Employee rule breakers, excuse makers and security champions: Mapping the risk perceptions and emotions that drive security behaviors, ACM International Conference Proceeding Series, 08-11-September-2015, pp. 73-84, (2015)
2 Renaud, Karen V., Shame in Cyber Security: Effective Behavior Modification Tool or Counterproductive Foil?, ACM International Conference Proceeding Series, pp. 70-87, (2021)
3 Schneier, Bruce, Secrets and Lies: DIGITAL SECURITY IN A NETWORKED WORLD, Secrets and Lies: Digital Security in a Networked World, pp. 1-414, (2015)
4 Vroom, Cheryl, Towards information security behavioural compliance, Computers and Security, 23, 3, pp. 191-198, (2004)
5 Ten Questions about Human Error A New View of Human Factors and System Safety, (2025)
6 Brostoff, Sacha, Safe and sound: A safety-critical approach to security, Proceedings New Security Paradigms Workshop, pp. 41-50, (2001)
7 Pfleeger, Shari Lawrence, Leveraging behavioral science to mitigate cyber security risk, Computers and Security, 31, 4, pp. 597-611, (2012)
8 Sasse, M. Angela, Transforming the 'weakest link' - A human/computer interaction approach to usable and effective security, BT Technology Journal, 19, 3, pp. 122-131, (2001)
9 Menges, Uta, Why IT Security Needs Therapy, Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 13106 LNCS, pp. 335-356, (2022)
10 Ashenden, Debi, Security Dialogues: Building Better Relationships between Security and Business, IEEE Security and Privacy, 14, 3, pp. 82-87, (2016)
Quick Actions
Full Text via DOI
Citation Metrics
1
Times Cited (Scopus)

References 10
Document Identifiers