Revealing the cyber security non-compliance "attribution gulf"
Ophoff, Jacques and Renaud, Karen; Bui, Tung X., ed. (2021) Revealing the cyber security non-compliance "attribution gulf". In: Proceedings of the 54th Annual Hawaii International Conference on System Sciences, HICSS 2021. Proceedings of the Annual Hawaii International Conference on System Sciences . University of Hawaii at Manoa, USA, pp. 4557-4566. ISBN 9780998133140
Preview |
Text.
Filename: Ophoff_Renaud_HICSS_2021_Revealing_the_cyber_security_non_compliance_attribution_gulf.pdf
Final Published Version License: Download (757kB)| Preview |
Abstract
Non-compliance is a well-known issue in the field of cyber security. Non-compliance usually manifests in an individual's sins of omission or commission, and it is easy to conclude that the problem is attributable to their personal flawed decision making. However, the individual's decision not to comply is likely also to be influenced by a range of environmental and contextual factors. Bordieu, for example, suggests that personal habitus influences decisions. We identified a wide range of possible explanations for non-compliance from the research literature and classified these, finding that a number of the identified factors were indeed habitus related. We then used Q-methodology to determine which of these non-compliance explanations aligned with public attributions of non-compliance causatives. We discovered an "attribution gulf", with popular opinion attributing non-compliance primarily to individual failings or ignorance. The existence of this attribution gap means that those designing cyber security interventions are likely to neglect the influence of habitus on choices and decisions. We need to broaden our focus if non-compliance is to be reduced.
ORCID iDs
Ophoff, Jacques and Renaud, Karen ORCID: https://orcid.org/0000-0002-7187-6531; Bui, Tung X.-
-
Item type: Book Section ID code: 77089 Dates: DateEvent5 January 2021Published23 August 2020AcceptedNotes: Nominated for Best Paper Award Subjects: Science > Mathematics > Electronic computers. Computer science Department: Faculty of Science > Computer and Information Sciences Depositing user: Pure Administrator Date deposited: 14 Jul 2021 13:21 Last modified: 11 Nov 2024 15:25 Related URLs: URI: https://strathprints.strath.ac.uk/id/eprint/77089