首页    期刊浏览 2024年12月13日 星期五
登录注册

文章基本信息

  • 标题:Addressing consumerization of IT risks with nudging
  • 本地全文:下载
  • 作者:Iryna Yevseyeva ; James Turland ; Charles Morisset
  • 期刊名称:International Journal of Information Systems and Project Management
  • 印刷版ISSN:2182-7796
  • 电子版ISSN:2182-7788
  • 出版年度:2015
  • 卷号:3
  • 期号:3
  • DOI:10.12821/ijispm030301
  • 出版社:SciKA
  • 摘要:In this work we address the main issues of Information Technology (IT) consumerization that are related to security risks, and vulnerabilities of devices used within Bring Your Own Device (BYOD) strategy in particular. We propose a 'soft' mitigation strategy for user actions based on nudging, widely applied to health and social behavior influence. In particular, we propose a complementary, less strict, more flexible Information Security policies, based on risk assessment of device vulnerabilities and threats to corporate data and devices, combined with a strategy of influencing security behavior by nudging. We argue that nudging, by taking into account the context of the decision-making environment, and the fact that the employee may be in better position to make a more appropriate decision, may be more suitable than strict policies in situations of uncertainty of security-related decisions. Several examples of nudging are considered for different tested and potential scenarios in security context.
  • 关键词:consumerization; security; risks; mitigation strategies; nudging
国家哲学社会科学文献中心版权所有