论文标题
规范和制裁是促进网络安全实践的基础
Norms and Sanctions as a Basis for Promoting Cybersecurity Practices
论文作者
论文摘要
由于用户不遵循良好的网络安全惯例,因此发生了许多网络安全漏洞,其中主要是将软件补丁应用于操作系统,更新应用程序和维护强密码的法规。 我们捕获对用户作为规范的网络安全期望。我们从经验上研究制裁机制,以促进遵守这些规范,以及制裁对用户完成工作能力的有害影响。我们在一个模拟研究实验室中模拟工人决策的游戏中意识到了这些想法。 通过一项人类受试者的研究,我们发现,尽管个人制裁在实现合规性方面比团体制裁更有效,并且对用户完成工作的能力的损害较小,但个人制裁的弹性却大大降低,尤其是对于包括寻求风险的组织的组织。我们的发现对网络安全方面的劳动力培训具有影响。
Many cybersecurity breaches occur due to users not following good cybersecurity practices, chief among them being regulations for applying software patches to operating systems, updating applications, and maintaining strong passwords. We capture cybersecurity expectations on users as norms. We empirically investigate sanctioning mechanisms in promoting compliance with those norms as well as the detrimental effect of sanctions on the ability of users to complete their work. We realize these ideas in a game that emulates the decision making of workers in a research lab. Through a human-subject study, we find that whereas individual sanctions are more effective than group sanctions in achieving compliance and less detrimental on the ability of users to complete their work, individual sanctions offer significantly lower resilience especially for organizations comprising risk seekers. Our findings have implications for workforce training in cybersecurity.