Issue No.03 - May-June (2012 vol.10)
Karen Renaud , University of Glasgow, Glasgow
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/MSP.2011.157
Information breaches demand a vigorous response from organizations. The traditional response is to institute policies to constrain and control employee behavior. Information security policies inform employees about appropriate uses of information technology in an organization. Unfortunately, limited evidence exists that such policies effectively reduce confidentiality breaches or information loss. This article explores the possible reasons for this and reports on a survey aiming to detect the presence of these factors in a UK National Health Service health board. This article argues that you must pay attention to the entire system, instead of focusing merely on individuals in the system. The survey shows how the pressures on the organization's staff members and the rules imposed by the policies often place staff in an impossible or untenable position. They sometimes feel this leaves them no option but to break the rules just to do their work. The Web extra is a list of additional resources.
information breaches, compliance, policies, computer security, information security
Karen Renaud, "Blaming Noncompliance Is Too Convenient: What Really Causes Information Breaches?", IEEE Security & Privacy, vol.10, no. 3, pp. 57-63, May-June 2012, doi:10.1109/MSP.2011.157