Hielscher, J;
Menges, U;
Parkin, S;
Kluge, A;
Sasse, MA;
(2023)
Employees Who Don't Accept the Time Security Takes Are Not Aware Enough": The CISO View of Human-Centred Security.
In:
SEC '23: Proceedings of the 32nd USENIX Conference on Security Symposium.
(pp. pp. 2311-2328).
ACM
Preview |
Text
sec23fall-prepub-110-hielscher.pdf - Accepted Version Download (279kB) | Preview |
Abstract
In larger organisations, the security controls and policies that protect employees are typically managed by a Chief Information Security Officer (CISO). In research, industry, and policy, there are increasing efforts to relate principles of human behaviour interventions and influence to the practice of the CISO, despite these being complex disciplines in their own right. Here we explore how well the concepts of humancentred security (HCS) have survived exposure to the needs of practice: in an action research approach we engaged with n = 30 members of a Swiss-based community of CISOs in five workshop sessions over the course of 8 months, dedicated to discussing HCS. We coded and analysed over 25 hours of notes we took during the discussions. We found that CISOs far and foremost perceive HCS as what is available on the market, namely awareness and phishing simulations. While they regularly shift responsibility either to the management (by demanding more support) or to the employees (by blaming them) we see a lack of power but also silo-thinking that prevents CISOs from considering actual human behaviour and friction that security causes for employees. We conclude that industry best practices and the state-of-the-art in HCS research are not aligned.
Type: | Proceedings paper |
---|---|
Title: | Employees Who Don't Accept the Time Security Takes Are Not Aware Enough": The CISO View of Human-Centred Security |
Event: | 32nd USENIX Security Symposium, USENIX Security 2023 |
ISBN-13: | 9781713879497 |
Open access status: | An open access version is available from UCL Discovery |
Publisher version: | https://dl.acm.org/doi/abs/10.5555/3620237.3620367 |
Language: | English |
Additional information: | This version is the author accepted manuscript. For information on re-use, please refer to the publisher’s terms and conditions. |
UCL classification: | UCL UCL > Provost and Vice Provost Offices > UCL BEAMS UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science > Dept of Computer Science |
URI: | https://discovery.ucl.ac.uk/id/eprint/10182428 |
Archive Staff Only
View Item |