A Novel Model for Monitoring Security Policy Compliance
Mutlaq Alotaibi, Steven Furnell, Nathan Clarke · Journal of Internet Technology and Secured Transaction · 2016
Organizations repeatedly suffer harm from employees who are not obeying or complying with their information security policies.Non-compliance behaviour of an employee, either unintentionally or intentionally, pose a real threat to an organization's information security.As such, more thought is needed on how to encourage employees to be security compliant and more in line with a security policy of their organization.As an initial approach to achieve this goal, we propose a model that is intended to provide a comprehensive framework for raising the level of compliance amongst end-users, with the aim of monitoring, measuring and responding to users' behaviour with an information security policy.The proposed approach is based on two main concepts: a taxonomy of the response strategy to noncompliance behaviour, and a compliance points system.The response taxonomy is comprised of two categories: awareness raising and enforcement of the security policy.The compliance points system is used to reward compliant behaviour, and penalise noncompliant behaviour.