Towards designing effective security messages: Persuasive password guidelines
The current state of information security compliance in workplaces is deteriorating. In many cases human factors were attributed as the cause of the problem.Humans are well known as the weakest link in the security chain.Commonly, end-users will depend on security messages when confronted with secur...
Saved in:
Main Authors: | , |
---|---|
Format: | Conference or Workshop Item |
Language: | English |
Published: |
2013
|
Subjects: | |
Online Access: | http://repo.uum.edu.my/13775/1/4.pdf http://repo.uum.edu.my/13775/ http://dx.doi.org/10.1109/ICRIIS.2013.6716697 |
Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Institution: | Universiti Utara Malaysia |
Language: | English |
Summary: | The current state of information security compliance in workplaces is deteriorating. In many cases human factors were attributed as the cause of the problem.Humans are well known as the weakest link in the security chain.Commonly, end-users will depend on security messages when confronted with security-related decision making. Most of the time, end-users will try their best to make sense of unclear instructions in order to cope with situations.This indicates the way security messages are presented is of utmost importance. However, research focusing on designing effective security messages is quite limited.This paper presents research in progress, towards designing effective security messages focusing on passwords guidelines.Our initial review indicated the lack of persuasive elements in the current password guidelines may lead to unmotivated behaviour of producing good (strong) passwords.This paper also includes initial results obtained from pilot study which reveal promising results supporting the usage of persuasion strategies to improve the current state information security compliance. |
---|