UCL Discovery
UCL home » Library Services » Electronic resources » UCL Discovery

Employees Who Don't Accept the Time Security Takes Are Not Aware Enough": The CISO View of Human-Centred Security

Hielscher, J; Menges, U; Parkin, S; Kluge, A; Sasse, MA; (2023) Employees Who Don't Accept the Time Security Takes Are Not Aware Enough": The CISO View of Human-Centred Security. In: SEC '23: Proceedings of the 32nd USENIX Conference on Security Symposium. (pp. pp. 2311-2328). ACM Green open access

[thumbnail of sec23fall-prepub-110-hielscher.pdf]
Preview
Text
sec23fall-prepub-110-hielscher.pdf - Accepted Version

Download (279kB) | Preview

Abstract

In larger organisations, the security controls and policies that protect employees are typically managed by a Chief Information Security Officer (CISO). In research, industry, and policy, there are increasing efforts to relate principles of human behaviour interventions and influence to the practice of the CISO, despite these being complex disciplines in their own right. Here we explore how well the concepts of humancentred security (HCS) have survived exposure to the needs of practice: in an action research approach we engaged with n = 30 members of a Swiss-based community of CISOs in five workshop sessions over the course of 8 months, dedicated to discussing HCS. We coded and analysed over 25 hours of notes we took during the discussions. We found that CISOs far and foremost perceive HCS as what is available on the market, namely awareness and phishing simulations. While they regularly shift responsibility either to the management (by demanding more support) or to the employees (by blaming them) we see a lack of power but also silo-thinking that prevents CISOs from considering actual human behaviour and friction that security causes for employees. We conclude that industry best practices and the state-of-the-art in HCS research are not aligned.

Type: Proceedings paper
Title: Employees Who Don't Accept the Time Security Takes Are Not Aware Enough": The CISO View of Human-Centred Security
Event: 32nd USENIX Security Symposium, USENIX Security 2023
ISBN-13: 9781713879497
Open access status: An open access version is available from UCL Discovery
Publisher version: https://dl.acm.org/doi/abs/10.5555/3620237.3620367
Language: English
Additional information: This version is the author accepted manuscript. For information on re-use, please refer to the publisher’s terms and conditions.
UCL classification: UCL
UCL > Provost and Vice Provost Offices > UCL BEAMS
UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science
UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science > Dept of Computer Science
URI: https://discovery.ucl.ac.uk/id/eprint/10182428
Downloads since deposit
15Downloads
Download activity - last month
Download activity - last 12 months
Downloads by country - last 12 months

Archive Staff Only

View Item View Item