Back to Search Start Over

Addressing consumerization of IT risks with nudging

Authors :
Iryna Yevseyeva
James Turland
Charles Morisset
Lynne Coventry
Thomas Groß
Christopher Laing
Aad van Moorsel
Source :
International Journal of Information Systems and Project Management, Vol 3, Iss 3 (2022)
Publication Year :
2022
Publisher :
UMinho Editora, 2022.

Abstract

In this work we address the main issues of Information Technology (IT) consumerization that are related to security risks, and vulnerabilities of devices used within Bring Your Own Device (BYOD) strategy in particular. We propose a ‘soft’ mitigation strategy for user actions based on nudging, widely applied to health and social behavior influence. In particular, we propose a complementary, less strict, more flexible Information Security policies, based on risk assessment of device vulnerabilities and threats to corporate data and devices, combined with a strategy of influencing security behavior by nudging. We argue that nudging, by taking into account the context of the decision-making environment, and the fact that the employee may be in better position to make a more appropriate decision, may be more suitable than strict policies in situations of uncertainty of security-related decisions. Several examples of nudging are considered for different tested and potential scenarios in security context.

Details

Language :
English
ISSN :
21827788
Volume :
3
Issue :
3
Database :
Directory of Open Access Journals
Journal :
International Journal of Information Systems and Project Management
Publication Type :
Academic Journal
Accession number :
edsdoj.964ac8d6a08f46af8e7d78d7f7c61609
Document Type :
article