Publication Details
Even if users do not read security directives, their behavior is not so catastrophic
Malinka Kamil, Mgr., Ph.D. (DITS FIT BUT)
Kraus Lydia, Dr.-Ing. (MUNI)
Knapová Lenka, Mgr. (MUNI)
Kružíková Agáta, RNDr. (MUNI)
security policy, usable security, user behaviour
We discuss an effort undertaken at Masaryk University (MU) a Czech university with some 30.000 students where we tried to improve our security directive to motivate users to follow it. From the research perspective, we also wanted to find out more about the current state of affairs from the user perspective: Do users (still not) follow the security policy? At the same time, the fact that our university IT infrastructure management had the intention to redesign the (outdated) security directive, constituted an ideal opportunity for us to deeper investigate the topic. And our initial faith has been hit hard as we describe in some detail in this viewpoint, but it wasnt a wasted effort at all. The data we obtained as a side effect shows a new perspective on this area.
@ARTICLE{FITPUB12874, author = "V\'{a}clav Maty\'{a}\v{s} and Kamil Malinka and Lydia Kraus and Lenka Knapov\'{a} and Ag\'{a}ta Kru\v{z}\'{i}kov\'{a}", title = "Even if users do not read security directives, their behavior is not so catastrophic", pages = "37--40", booktitle = "Communications of the ACM", journal = "Communications of the ACM", volume = 65, number = 1, year = 2022, location = " New York, US", ISSN = "0001-0782", doi = "10.1145/3471928", language = "english", url = "https://www.fit.vut.cz/research/publication/12874" }