2017 Seventh International Conference on Emerging Security Technologies (EST) 2017
DOI: 10.1109/est.2017.8090409
|View full text |Cite
|
Sign up to set email alerts
|

Readability as a basis for information security policy assessment

Abstract: Most organisations now impose information security policies (ISPs) or 'conditions of use' agreements upon their employees. The need to ensure that employees are informed and aware of their obligations toward information security is apparent. Less apparent is the correlation between the provision of such policies and their compliance. In this paper, we report our research into the factors that determine the efficacy of information security policies (ISPs). Policies should comprise rules or principles that users… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

0
4
0

Year Published

2019
2019
2022
2022

Publication Types

Select...
3
2

Relationship

0
5

Authors

Journals

citations
Cited by 6 publications
(4 citation statements)
references
References 18 publications
(19 reference statements)
0
4
0
Order By: Relevance
“…This raised the question of adding understandability as an aspect of the information security principle of Availability. Within the information security field, understandability has been studied from the perspective of understanding and compliance with information security policies (Alkhurayyif and Weir, 2017; Nel and Drevin, 2019), but not from the perspective of being an aspect of availability. In an organization such as the municipality where communication of information to the public is one of the most important tasks, whether the communicated information is understood by the receiver of that information, is directly related to the availability of that information.…”
Section: Discussionmentioning
confidence: 99%
“…This raised the question of adding understandability as an aspect of the information security principle of Availability. Within the information security field, understandability has been studied from the perspective of understanding and compliance with information security policies (Alkhurayyif and Weir, 2017; Nel and Drevin, 2019), but not from the perspective of being an aspect of availability. In an organization such as the municipality where communication of information to the public is one of the most important tasks, whether the communicated information is understood by the receiver of that information, is directly related to the availability of that information.…”
Section: Discussionmentioning
confidence: 99%
“…Work by Alkhurayyif and Weir [13] points to readability metrics for countermeasure text assessment to improve users' compliance to controls. By analyzing cybersecurity protection motivation through the lens of an extended PMT model, this paper has clarified how countermeasure readability influences security intentions.…”
Section: Discussionmentioning
confidence: 99%
“…Yet, earlier work exists and has formed an inspiration for our approach. Alkhurayyif and Weir [13] compared the eight most popular traditional readability metrics against manual human comprehension metrics in information security policies (ISPs) and demonstrated a correlation between human and computer metrics.…”
Section: Readability Of Cybersecurity Countermeasuresmentioning
confidence: 99%
See 1 more Smart Citation