错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Overcoming Policy Fatigue and Non-compliance

  • Magen Burkitt,
  • Daniel Patricko Hutabarat

摘要

Technology has become pervasive in almost every aspect of life, resulting in the need for all individuals to become technically literate in order to improve their personal security competency and protect their own privacy. In an organisational setting, such security requirements are addressed via a combination of technical and administrative control mechanisms, including a raft of policies that dictate how technology is used and managed within the corporate setting. In a hybrid environment that includes corporate information technology (IT) and Bring Your Own Device (BYOD), there becomes a need to redesign policy and realign expectations and responsibilities. Where controls and expectations exceed a user’s ability to comprehend their role, or where a user disagrees with the requirements, the result may lead to an increase in stress on the part of the employee resulting in non-compliance, contributing to security vulnerabilities for the organisation. A literature review has been undertaken to identify the contributing factors to policy fatigue and if the introduction of BYOD initiatives into the workplace leads to additional levels of stress and non-compliance as employees attempt to align personal and professional IT security behaviours. This review contributes to this topic by identifying key human-centric issues in what is often view as a technical challenge. It also highlights the divide between the academic analysis of this problem and the practical identification and implementation of solutions to support better levels of compliance through effective administrative controls including policy.