2015
DOI: 10.1145/2738210.2738216
|View full text |Cite
|
Sign up to set email alerts
|

"Shadow security" as a tool for the learning organization

Abstract: Traditionally, organizations manage information security through policies and mechanisms that employees are expected to comply with. Non-compliance with security is regarded as undesirable, and often sanctions are threatened to deter it. But in a recent study, we identified a third category of employee security behavior: shadow security. This consists of workarounds employees devise to ensure primary business goals are achieved; they also devise their own security measures to counter th… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
30
0

Year Published

2015
2015
2023
2023

Publication Types

Select...
4
4
1

Relationship

2
7

Authors

Journals

citations
Cited by 41 publications
(30 citation statements)
references
References 21 publications
0
30
0
Order By: Relevance
“…Non-compliance is an opportunity for security managers to make security better [12]. Kirlappos et al [6] identified the following main reasons for non-compliance:…”
Section: Methodsmentioning
confidence: 99%
“…Non-compliance is an opportunity for security managers to make security better [12]. Kirlappos et al [6] identified the following main reasons for non-compliance:…”
Section: Methodsmentioning
confidence: 99%
“…The social practice of security 8 flourishes in the compromises and gaps between the processes that seek to shepherd the activities and outputs of security enactment. 9 It's here that we see an opportunity to improve security dialogues, risk communication, and security culture.…”
Section: Social Practice Of Securitymentioning
confidence: 99%
“…Information security policy can prompt employees to consult with experts before any action in a suspicious situation, such as phishing, social engineering and misleading software. Information security policies and procedures should be clear and easy to understand (Kirlappos, Parkin et al, 2015). These policies should be updated frequently due to the dynamic nature of the threats (Ifinedo, 2014).…”
Section: Complaining With Organizational Policiesmentioning
confidence: 99%