An Instrument to Measure Human Behavior Toward Cyber Security Policies

Dr. Khalid Adnan Alissa, H. A. Alshehri, S. A. Dahdouh, B. M. Alsubaie, Afnan M. Alghamdi, Dr. Abdulrahman Alharby, N. A. Almubairik
{"title":"An Instrument to Measure Human Behavior Toward Cyber Security Policies","authors":"Dr. Khalid Adnan Alissa, H. A. Alshehri, S. A. Dahdouh, B. M. Alsubaie, Afnan M. Alghamdi, Dr. Abdulrahman Alharby, N. A. Almubairik","doi":"10.1109/NCG.2018.8592978","DOIUrl":null,"url":null,"abstract":"Human is the weakest link in information security. Even with strong cyber security policies an organization can still be hacked because of a human error. Even if people are aware of the policies and their importance they might not behave accordingly. This shows to the importance of studying and measuring human behavior toward cyber security policies. This paper introduces a new instrument that can be used to measure human behavior toward cybersecurity policies through creative measures. The goal is to gather data about human behaviors toward cybersecurity policies in natural environment. This method of gathering information allows people to behave normally and don’t feel the need to answer perfectly. The paper illustrates all the previous work related to the subject, summarizing previous work in order to improve what have been previously done. The methodology seeks on measuring behavior based on specific measures. These measures are the password, email, identity, sensitive data, and physical/resource security. Each measure has a number of policies used to measure behavior. These policies were selected among several policies based on literature from the same field and the opinion of experts in the field. These question that went through several rounds of check were used to build the proposedinstrument. This instrument then shall be used by researchers to collect data and perform the required analysis. This paper discusses the behavior pattern in a detail and concise manner. The paper demonstrates that it is posable to measure behavior if the right we questions were asked in the right way.","PeriodicalId":305464,"journal":{"name":"2018 21st Saudi Computer Society National Computer Conference (NCC)","volume":"31 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-04-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 21st Saudi Computer Society National Computer Conference (NCC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/NCG.2018.8592978","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

Human is the weakest link in information security. Even with strong cyber security policies an organization can still be hacked because of a human error. Even if people are aware of the policies and their importance they might not behave accordingly. This shows to the importance of studying and measuring human behavior toward cyber security policies. This paper introduces a new instrument that can be used to measure human behavior toward cybersecurity policies through creative measures. The goal is to gather data about human behaviors toward cybersecurity policies in natural environment. This method of gathering information allows people to behave normally and don’t feel the need to answer perfectly. The paper illustrates all the previous work related to the subject, summarizing previous work in order to improve what have been previously done. The methodology seeks on measuring behavior based on specific measures. These measures are the password, email, identity, sensitive data, and physical/resource security. Each measure has a number of policies used to measure behavior. These policies were selected among several policies based on literature from the same field and the opinion of experts in the field. These question that went through several rounds of check were used to build the proposedinstrument. This instrument then shall be used by researchers to collect data and perform the required analysis. This paper discusses the behavior pattern in a detail and concise manner. The paper demonstrates that it is posable to measure behavior if the right we questions were asked in the right way.
衡量人类对网络安全政策行为的工具
人是信息安全中最薄弱的环节。即使有强大的网络安全政策,一个组织仍然可能因为人为错误而被黑客入侵。即使人们意识到这些政策及其重要性,他们也可能不会采取相应的行动。这表明了研究和衡量人类行为对网络安全政策的重要性。本文介绍了一种新的工具,可以通过创造性的措施来衡量人类对网络安全政策的行为。目标是收集自然环境下人类对网络安全政策的行为数据。这种收集信息的方法可以让人们表现得正常,而不会觉得有必要完美地回答。本文阐述了与本课题相关的所有以前的工作,总结了以前的工作,以便改进以前所做的工作。该方法寻求以具体措施为基础来衡量行为。这些措施包括密码、电子邮件、身份、敏感数据和物理/资源安全。每个度量都有许多用于度量行为的策略。这些政策是根据同一领域的文献和该领域专家的意见从若干政策中选择出来的。这些经过几轮检查的问题被用来构建提议的仪器。该仪器随后由研究人员收集数据并进行所需的分析。本文详细而简明地讨论了行为模式。本文表明,如果以正确的方式提出正确的问题,就有可能衡量行为。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信