A Concept Proposal on Modeling of Security Fatigue Level
Shigeaki Tanimoto, Keita Nagai, Hata Ken'ichiro, Takashi Hatashima, Sakamoto Yasuhisa, Atsushi Kanai · 2017
The threat of cybercrimes has recently increased as the Internet has becomes more of a necessity. Therefore, the importance of information security is also increasing. In addition to information-security technology, determining an information-security policy is important. For example, in the information security management system, the three elements of confidentiality, availability, and integrity are maintained with sufficient balance, enabling continuous improvement. However, a strict information-security policy may decrease security consciousness of the employee of a field. A report of the National Institute of Standards and Technology also defines the fatigue produced by carrying out computer-safety measures as "Security Fatigue". In this paper, we propose a model for visualizing the security-fatigue level. We evaluated the model and found that it contributes to a safe and secure ICT infrastructure.