依赖特定计算平台的计算机安全自满:未被识别的内部威胁

Platform-Dependent Computer Security Complacency: The Unrecognized Insider Threat

IEEE Transactions on Engineering Management · 2021
被引 14
ABS 3

中文导读

通过扎根理论研究,识别出计算机用户安全自满的三种类型:固有自满、平台自满和社会自满,揭示了内部威胁的新来源。

Abstract

This article reports on a grounded theory investigation of subject response anomalies that were encountered in the course of a neurocognitive laboratory study of computer user cybersecurity behaviors. Subsequent qualitative data collection led to theoretical development in specification of three broad constructs of computer user security complacency. Theoretical insights indicate that states of security complacency can arise in the form of a naïve lack of concern about the likelihood of facing security threats (inherent complacency), from ill-advised dependence upon specific computing platforms and protective workplace technology implementations for protection (platform complacency), as well as the reliance on the guidance on advice from trusted social others in personal and workplace networks (social complacency). Elements of an emergent theory of cybersecurity complacency arising from our interpretive insights are discussed.

计算机安全内部威胁用户行为网络安全定性研究