SIG SEC - Information Security and Privacy

Loading...

Media is loading
 

Paper Type

ERF

Paper Number

1105

Description

Lack of employee compliance with information security policies is a key factor driving security incidents. Information security practitioners struggle to enforce policy compliance while employees try to curtail controls in favor of expediency and other perceived business and personal goals. This research-in-progress project utilizes the Design Science Research framework to develop an intervention based on a novel messaging strategy that aims to help information security practitioners improve employees’ behaviors through intrinsic motivation, thus increasing compliance with information security policies.

Comments

SIG SEC

Share

COinS
 
Aug 10th, 12:00 AM

Designing a Messaging Strategy to Improve Information Security Policy Compliance

Lack of employee compliance with information security policies is a key factor driving security incidents. Information security practitioners struggle to enforce policy compliance while employees try to curtail controls in favor of expediency and other perceived business and personal goals. This research-in-progress project utilizes the Design Science Research framework to develop an intervention based on a novel messaging strategy that aims to help information security practitioners improve employees’ behaviors through intrinsic motivation, thus increasing compliance with information security policies.

When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.