The Experts below are selected from a list of 11514 Experts worldwide ranked by ideXlab platform

Catherine E Connelly - One of the best experts on this subject based on the ideXlab platform.

  • Understanding Nonmalicious Security Violations in the Workplace: A Composite Behavior Model
    Journal of Management Information Systems, 2011
    Co-Authors: Ken H. Guo, Norman P Archer, Yufei Yuan, Catherine E Connelly
    Abstract:

    End users are said to be "the weakest link" in information systems (IS) Security management in the workplace. They often knowingly engage in certain insecure uses of IS and violate Security policies without malicious intentions. Few studies, however, have examined end user motivation to engage in such behavior. To fill this research gap, in the present study we propose and test empirically a nonmalicious Security Violation (NMSV) model with data from a survey of end users at work. The results suggest that utilitarian outcomes (relative advantage for job performance, perceived Security risk), normative outcomes (workgroup norms), and self-identity outcomes (perceived identity match) are key determinants of end user intentions to engage in NMSVs. In contrast, the influences of attitudes toward Security policy and perceived sanctions are not significant. This study makes several significant contributions to research on Security-related behavior by (1) highlighting the importance of job performance goals and Security risk perceptions on shaping user attitudes, (2) demonstrating the effect of workgroup norms on both user attitudes and behavioral intentions, (3) introducing and testing the effect of perceived identity match on user attitudes and behavioral intentions, and (4) identifying nonlinear relationships between constructs. This study also informs Security management practices on the importance of linking Security and business objectives, obtaining user buy-in of Security measures, and cultivating a culture of secure behavior at local workgroup levels in organizations. [ABSTRACT FROM AUTHOR]

Ken H. Guo - One of the best experts on this subject based on the ideXlab platform.

  • Understanding Nonmalicious Security Violations in the Workplace: A Composite Behavior Model
    Journal of Management Information Systems, 2011
    Co-Authors: Ken H. Guo, Norman P Archer, Yufei Yuan, Catherine E Connelly
    Abstract:

    End users are said to be "the weakest link" in information systems (IS) Security management in the workplace. They often knowingly engage in certain insecure uses of IS and violate Security policies without malicious intentions. Few studies, however, have examined end user motivation to engage in such behavior. To fill this research gap, in the present study we propose and test empirically a nonmalicious Security Violation (NMSV) model with data from a survey of end users at work. The results suggest that utilitarian outcomes (relative advantage for job performance, perceived Security risk), normative outcomes (workgroup norms), and self-identity outcomes (perceived identity match) are key determinants of end user intentions to engage in NMSVs. In contrast, the influences of attitudes toward Security policy and perceived sanctions are not significant. This study makes several significant contributions to research on Security-related behavior by (1) highlighting the importance of job performance goals and Security risk perceptions on shaping user attitudes, (2) demonstrating the effect of workgroup norms on both user attitudes and behavioral intentions, (3) introducing and testing the effect of perceived identity match on user attitudes and behavioral intentions, and (4) identifying nonlinear relationships between constructs. This study also informs Security management practices on the importance of linking Security and business objectives, obtaining user buy-in of Security measures, and cultivating a culture of secure behavior at local workgroup levels in organizations. [ABSTRACT FROM AUTHOR]

Bryan Fuller - One of the best experts on this subject based on the ideXlab platform.

  • onlooker effect and affective responses in information Security Violation mitigation
    Computers & Security, 2021
    Co-Authors: Sahar Farshadkhah, Craig Van Slyke, Bryan Fuller
    Abstract:

    Abstract The average total cost of a Security Violation in the United States grew to almost $8 million in 2018. Still, current employees are the top source of Security incidents. Many insider threats to cyberSecurity are not malicious but are intentional. Many organizations have well-delineated policies intended to guide insiders’ cyberSecurity-related behaviors. However, the effectiveness of these policies is questionable. While many behavioral research projects have investigated factors that mitigate information Security Violations, there is still a need to better understand workplace social dynamics as a contributing factor. This study investigates the perception of being observed by onlookers as one of these factors. Using an experimental design, this study found that the perceived presence of an onlooker who presents a threat results in potential violators experiencing negative emotions (shame and guilt). Feelings of guilt reduce intentions to violate information Security policy in a workplace.

Jan Lehnhardt - One of the best experts on this subject based on the ideXlab platform.

  • a comprehensive approach to anomaly detection in relational databases
    Lecture Notes in Computer Science, 2005
    Co-Authors: Adrian Spalka, Jan Lehnhardt
    Abstract:

    Anomaly detection systems assume that a certain deviation from the regular behaviour of a system can be an indicator for a Security Violation. They proved their usefulness to networks and operating systems for a long time, but are much less prominent in the field of databases. Relational databases operate on attributes within relations, ie, on data with a very uniform structure, which makes them a prime target for anomaly detection systems. This work presents such a system for the database extension and the user interaction with a DBMS; it also proposes a misuse detection system for the database scheme. In a comprehensive investigation we compare two approaches to deal with the database extension, one based on reference values and one based on Δ-relations, and show that already standard statistical functions yield good detection results. We then apply our methods to the user interaction, which is split into user input and DBMS behaviour. All methods have been implemented in a semi-automatic anomaly detection tool for the MS SQL Server 2000.

Luis Fernandezluque - One of the best experts on this subject based on the ideXlab platform.

  • analysis of health professional Security behaviors in a real clinical setting an empirical study
    International Journal of Medical Informatics, 2015
    Co-Authors: Jose Luis Fernandezaleman, Ana Sanchezhenarejos, Ambrosio Toval, Ana Belen Sanchezgarcia, Isabel Hernandezhernandez, Luis Fernandezluque
    Abstract:

    Abstract Objective The objective of this paper is to evaluate the Security behavior of healthcare professionals in a real clinical setting. Method Standards, guidelines and recommendations on Security and privacy best practices for staff personnel were identified using a systematic literature review. After a revision process, a questionnaire consisting of 27 questions was created and responded to by 180 health professionals from a public hospital. Results Weak passwords were reported by 62.2% of the respondents, 31.7% were unaware of the organization's procedures for discarding confidential information, and 19.4% did not carry out these procedures. Half of the respondents (51.7%) did not take measures to ensure that the personal health information on the computer monitor could not be seen by unauthorized individuals, and 57.8% were unaware of the procedure established to report a Security Violation. The correlation between the number of years in the position and good Security practices was not significant (Pearson's r =0.085, P =0.254). Age was weakly correlated with good Security practices (Pearson's r =−0.169, P =0.028). A Mann–Whitney test showed no significant difference between the respondents' Security behavior as regards gender ( U =2536, P =0.792, n =178). The results of the study suggest that more efforts are required to improve Security education for health personnel. Conclusions It was found that both preventive and corrective actions are needed to prevent health staff from causing Security incidents. Healthcare organizations should: identify the types of information that require protection, clearly communicate the penalties that will be imposed, promote Security training courses, and define what the organization considers improper behavior to be and communicate this to all personnel.