Finding Security Champions in Blends of Organisational Culture

نویسندگان

  • Ingolf Becker
  • Simon Parkin
  • M. Angela Sasse
چکیده

Security managers define policies and procedures to express how employees should behave to ‘do their bit’ for information security. They assume these policies are compatible with the business processes and individual employees’ tasks as they know them. Security managers usually rely on the ‘official’ description of how those processes are run; the dayto-day reality is different, and this is where security policies can cause friction. Organisations need employees to participate in the construction of workable security, by identifying where policies causes friction, are ambiguous, or just do not apply. However, current efforts to involve employees in security act to identify employees who can be local representatives of policy — as with the currently popular idea of ‘security champions’ — rather than as a representative of employee security needs. Towards helping organisations ‘close the loop’ and get input from employees, we have conducted employee surveys on security in the context of their specific jobs. The paper presents results from secondary analysis of one such survey in a large commercial organisation. The analysis of 608 responses finds that attitude to policy and behaviour types — the prevailing security cultures — vary greatly in the organisation and across four business divisions examined in further detail. There is a role in contributing to the effectiveness of security policies not only for those who follow policy, but also for those who question policy, socialise solutions, or expect security to justify itself as a critical part of their productive work. This demonstrates that security champions cannot be uniform across the organisation, but rather that organisations should re-think the role of security champions as diverse ‘bottom-up’ agents to change policy for the better, rather than communicators of existing ‘top-down’ policies.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Organisational champions of IT innovation

This paper reports on an investigation of the characteris 'GSCJf-tQ-organisation al champions of information technology (IT) innovation in The N erlands. The institutions at which they work are in the financial, transport, govemmeyt--' nd software sectors. Much of the research in this area has focused considerable attention on the individual personality traits of champions. This research projec...

متن کامل

The Role of Security Culture

This chapter provides a discussion of the importance of the wider organisational context that the network administrator needs to deal with by describing how the organisational culture can impact on the degree to which security can be successfully maintained. It starts with an acknowledgement of the general clusters of factors that affect security (technology, processes, organisational, and huma...

متن کامل

The Role of Security Culture

This chapter provides a discussion of the importance of the wider organisational context that the network administrator needs to deal with by describing how the organisational culture can impact on the degree to which security can be successfully maintained. It starts with an acknowledgement of the general clusters of factors that affect security (technology, processes, organisational, and huma...

متن کامل

The Role of Security Culture

This chapter provides a discussion of the importance of the wider organisational context that the network administrator needs to deal with by describing how the organisational culture can impact on the degree to which security can be successfully maintained. It starts with an acknowledgement of the general clusters of factors that affect security (technology, processes, organisational, and huma...

متن کامل

Psychometric Properties of the Clinical Learning Organisational Culture Survey (CLOCS)‌ government educational hospitals in Rasht

Introduction: There is a dearth of standardized instrument to ass the lifelong leaning capabilities of nurses. This study aimed at evaluating some of the psychometric properties of the Clinical Learning Organisational Culture Survey (CLOCS) in Iranian context. Methods: The sample study comprised of 327 nursing staff affiliated to government educational hospitals in Rasht- I. R Iran during 2013...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2017