Naïve and Accidental Behaviours that Compromise Information Security: What the Experts Think.

Dragana Calic, Malcolm Pattinson, Kathryn Parsons, Marcus Butavicius, Agata McCormac · Adelaide Research & Scholarship (AR&S) (University of Adelaide) · 2016

The aim of the present study was twofold. First it aimed to elicit Information Security (InfoSec) experts’ perceptions about the most important naïve and accidental behaviours that could compromise the InfoSec of an organisation. The second aim was to use these findings to assess the relevance of behaviours that are currently measured by the Human Aspects of Information Security Questionnaire (HAIS-Q), with the intention to further validate the instrument. We employed a qualitative, focus group data collection approach, which enabled rich discussion with InfoSec experts. Fifteen InfoSec experts were asked: “What naïve and accidental behaviours could compromise the information security of an organisation?” They brainstormed, discussed and rated the most important behaviours. According to these experts, the three most important behaviours were sharing passwords, not considering the consequences of Social Media (SM), and oversharing information on SM. It was also found that, of the eleven most important behaviours, rated by the InfoSec experts, eight were part of the HAIS-Q. Furthermore, discussions emphasised the notion of human naivety, lending support to the focus on naïve and accidental behaviours. Finally, our findings demonstrate that behaviours measured by the HAIS-Q are relevant, providing validation for the HAIS-Q.

Read the paper · More papers on PaperTik