1 / 11100%
1
Running Head: HUMAN COMPLIANCE
HUMAN COMPLIANCE
CARLA GINART
LIBERTY UNIVERSITY
CSCI612_B01_202420
FEBRUARY 15, 2024
HUMAN COMPLIANCE 2
Introduction
Threats to information security have a detrimental effect on businesses. For these risks to be
eliminated or significantly reduced, organizations depend on employee adherence to information
security policies. To determine the elements that could influence employees' intentions and
behavior about adherence to information security policies and policies in a global context, the
Unified Model of Information Security Policies Compliance (UMISPC) is utilized. Information
is a precious commodity in the modern world. Professional associations must therefore give
information systems security policies top priority. 59% of businesses in the US and UK reported
security issues in 2019. Data breaches surged by 160% between 2006 and 2019, affecting 25,575
records in that year alone. At the same time, 230,000 new malware samples are created every
day, and more than 4000 ransomware assaults take place each day. Ninety-one per cent of these
infiltrate businesses using spear phishing emails, with 2019 damage costs exceeding $11.5
billion globally. Information security threats have a severe negative impact on enterprises.
Organizations rely on employee compliance with information security policies to eliminate or
reduce these hazards. The COVID-19 pandemic in 2020 presented criminals with an opportunity
to capitalize on the rise in telecommuting and cloud migration in the UK IT services.
Additionally, the number of Americans working from home rose from 6% to 35% in 2020, and
during the first six weeks of the lockdown, attacks on those working from home jumped from
12% to 60%. Hospitals, governments, and educational institutions are more likely to have paid
ransoms to prevent additional disruptions to their systems as a result of the COVID-19
pandemic. In addition to this pressure, NIST notes that people are the primary ransomware
attack facilitators. Risky behavior by end users, unsafe system configurations by administrators,
and secure development practices ignorance among developers.
HUMAN COMPLIANCE 3
Research Objectives
What is information security and how does that tie in with Security Engineering?
What is human compliance and how does that work with information security?
Describe how human error can be a big problem when it comes security policies.
Describe how HIPPA demonstrates how human error can really damage an organization?
Describe how important it is to make sure human compliance is carried out.
Research Questions
1. Does human compliance make information security hard to maintain?
2. How and why does human error cause problems when trying to information security?
3. Can human compliance really cause damage to a company?
HUMAN COMPLIANCE 4
Reference Choices
Alraja, M. N., Butt, U. J., & Abbod, M. (2023). Information security policies compliance in
a global setting: An employee's perspective.Computers & Security,129,
103208.2https://doi.org/10.1016/j.cose.2023.103208
This is the article I choose to do my research paper on. I choose this article because it discusses.
Information security policies and how employee compliance is an important part of that. “59% of
businesses in the US and UK reported security issues in 2019. Data breaches surged by 160%
between 2006 and 2019, affecting 25,575 records in that year alone. At the same time, 230,000
newAmalware samplesAare created every day, and more than 4000AransomwareAassaults take place
each day. Ninety-one per cent of these infiltrate businesses using spear phishing emails, with
2019 damage costs exceeding $11.5 billion globally.” (Alraja, 2023) These numbers are
staggering and worth taking a deeper look into, and that is why I choose this topic for my
research paper.
Anderson. (n.d.). Multilevel Security - University of Cambridge. Multilevel Security.
https://www.cl.cam.ac.uk/~rja14/Papers/SEv2-c08.pdf
I choose this article because it is one of our resources for this course and I wanted to make sure
to incorporate it into the paper. It also helps me explain more about what a security policy is and
how this works with security engineering. “Where a top-down approach to security engineering
is possible, it will typically take the form of threat model — security policy — security
mechanisms. The critical, and often neglected, part of this process is the security policy”
(Anderson, n.d.)
Basta, Alfred 2023.2Security Engineering. McGraw Hill
https://bookshelf.vitalsource.com/books/9781307917031
HUMAN COMPLIANCE 5
I choose this book as one of my resources because it is our course book and I also wanted to
make sure to use course material to tie in everything for the research paper. I am going to be
looking at chapter 5 because this goes over social engineering, and that is what can cause human
compliance to not happen and is why human error ends up costing organizations lots of money.
“Social engineering attacks that focus on tricking users are almost always successful. Users often
make serious mistakes that create vulnerabilities. Sometimes, users intentionally bypass security,
such as creating unauthorized network connections with the honest intention of “getting the job
done” without fully appreciating the risk they create for the mission of their organization.”
(Basta, 2023) “Now the serpent was more crafty than any other beast of the field that the Lord
God had made. He said to the woman, “Did God actually say, ‘You shall not eat of any tree in
the garden’?” And the woman said to the serpent, “We may eat of the fruit of the trees in the
garden, but God said, ‘You shall not eat of the fruit of the tree that is in the midst of the garden,
neither shall you touch it, lest you die.’” But the serpent said to the woman, “You will not surely
die. For God knows that when you eat of it your eyes will be opened, and you will be like God,
knowing good and evil.” -Genesis 3:1-24
Kang, P. , Kang, J. & Monsen, K.2(2022).2Nurse Information Security Policy Compliance,
Information Competence, and Information Security Attitudes Predict Information
Security Behavior.2CIN: Computers, Informatics, Nursing,Publish Ahead of
Print,2doi: 10.1097/CIN.0000000000000981.
I choose the reference above because I have always felt that humans/employees were one of the
biggest weaknesses when it comes to cybersecurity. It is the topic I choose to do the research
paper on. This article allows me to dig deeper into this thought even though it mainly deals with
just how nurses cause data breaches and how much of a cost that can be for healthcare alone.
HUMAN COMPLIANCE 6
This shows how much of an impact human compliance really does have on information security.
“God is not man, that he should lie, or a son of man, that he should change his mind. Has he said,
and will he not do it? Or has he spoken, and will he not fulfill it?” -Numbers 23:29 God knows
that human error is always possible. Every human in the world makes mistakes. But with the
right teachings whether it be through the Bible, or making sure employees are properly trained in
cybersecurity, can make sure that humans are less prone to make mistakes and are always trying
to do the right thing.
Lee, D., Lallie, H.S. & Michaelides, N. The impact of an employee’s psychological contract
breach on compliance with information security policies: intrinsic and extrinsic
motivation.2Cogn Tech Work225, 273–289 (2023). https://doi.org/10.1007/s10111-023-
00727-5
I choose this article to review because it helps to show how not all employees are compliant with
information security policies to the extent that organizations expect them to be. This helps
support the idea that human compliance and human error is a big factor in information security
policies and can make it difficult to ensure that the policies work. It also discusses the
psychological factors that come into when this happens, which might help minimize human error
down the road. “Organizational information security breaches can largely be explained by
human error and omission (ISF 2020). In other words, if employees deliberately or
unintentionally fail to keep the information safe, it is insufficient to take technical
countermeasures for the protection of the information. Accordingly, various psychological
factors motivating employees’ failure to comply with ISP compliance have been raised in the
cyber security literature. Among them, the psychological contract was presented as one of
the significant human factors provoking employees’ cybersecurity behaviors.” (Lee, 2023)
HUMAN COMPLIANCE 7
Mihai, T. (2018). Jesus Christ: Ethics Lessons for Project Managers. The Journal of
Biblical Integration in Business, 21(1), 81-92.
https://cbfa-jbib.org/index.php/jbib/article/view/495/503
I choose this article to help support my research topic, because it helps support my research
biblically. It also discusses ethics. Ethics play a big part in whether or not an employee will
make sure to do the right thing and keep their patients health information private. “In projects
that are complex—with significant budget, content, and time constraints—the notion of ethics
becomes more important because the planning and execution of projects depend on the
availability of accurate and true information, allowing project managers to make appropriate
assessments and decisions.” (Mihai, 2018) “So whatever you wish that others would do to you,
do also to them, for this is the Law and the Prophets.” -Matthew 7:12
Nifakos, S., Chandramouli, K., Nikolaou, C. K., Papachristou, P., Koch, S., Panaousis, E.,
& Bonacina, S. (2021). Influence of Human Factors on Cyber Security within
Healthcare Organisations: A Systematic Review.2Sensors (Basel,
Switzerland),221(15), 5119. https://doi.org/10.3390/s21155119
I choose this article because it goes over human factors on cyber security with a healthcare
organization. I am using HIPPA and the healthcare organization to help show how big of an
issue human error is and how costly it can be for organizations. “Cybersecurity is increasingly
becoming a prominent concern among healthcare providers in adopting digital technologies for
improving the quality of care delivered to patients. The recent reports on cyber-attacks, such as
ransomware and WannaCry, have brought to life the destructive nature of such attacks upon
healthcare. In complement to cyberattacks, which have been targeted against the vulnerabilities
of information technology (IT) infrastructures, a new form of cyber-attack aims to exploit human
HUMAN COMPLIANCE 8
vulnerabilities; such attacks are categorized as social engineering attacks.” (Nifakos, 2021) “No
weapon that is fashioned against you shall succeed, and you shall refute every tongue that rises
against you in judgment. This is the heritage of the servants of the Lord and their vindication
from me, declares the Lord.” -Isaiah 54:17 Human error is a thing similar to the weapon
mentioned in the Bible verse above, however with the right security policies and training and
effort in place it will be something that won’t succeed.
Olukoya, O. (2022). Assessing frameworks for eliciting privacy & security requirements
from laws and regulations. Computers & Security, 117, 102697.
https://doi.org/10.1016/j.cose.2022.102697
I choose this article because it discusses how security policies and laws and legislations must
work together. HIPPA is discussed in this article and will help me show how HIPPA ties in with
information security and security engineering. “Different laws and legislation have been
introduced to standardize and strengthen data protection policies across different countries to
protect such data. Therefore, businesses and organizations responsible for managing personal
data are obligated to implement the privacy and security requirements established by these laws
and legislation.” (Olukoya, 2022) “Now we know that the law is good, if one uses it lawfully,
understanding this, that the law is not laid down for the just but for the lawless and disobedient,
for the ungodly and sinners, for the unholy and profane, for those who strike their fathers and
mothers, for murderers, the sexually immoral, men who practice homosexuality, enslavers, liars,
perjurers, and whatever else is contrary to sound doctrine,” -1 Timothy 1:8-10
Sarkar, S. , Vance, A. (2020). The Influence of Professional Subculture on Information
Security Policy Violations: A Field Study in a Healthcase Context. Information
Systems Research, 31(4), 1037-1492. https://doi.org/10.1287/isre.2020.0941
HUMAN COMPLIANCE 9
I am using the article to support my research paper because it digs into how data privacy
breaches can really be costly to a healthcare organization.The frequency of data breaches has
increased in a huge amount over the years, especially with the advancement of technology and
new ways for cyber criminals to attack a system. This means the cost of data breaches has also
risen. An average incident cost of a data breach in the United States is around $8.19 million. This
is especially true of the healthcare industry, which has experienced increased numbers of
personal health information (PHI) breaches. The cost of data breaches is by far the highest in
healthcare: the per capita cost is over twice that of the next highest industry.” (Sarkar, 2020)
“The thief comes only to steal and kill and destroy. I came that they may have life and have it
abundantly.” -John 10:10
HUMAN COMPLIANCE 10
References
Alraja, M. N., Butt, U. J., & Abbod, M. (2023). Information security policies compliance in a
global setting: An employee's perspective.Computers & Security,129,
103208.Ahttps://doi.org/10.1016/j.cose.2023.103208
Anderson. (n.d.). Multilevel Security - University of Cambridge. Multilevel Security.
https://www.cl.cam.ac.uk/~rja14/Papers/SEv2-c08.pdf
Basta, Alfred 2023.ASecurity Engineering. McGraw Hill
https://bookshelf.vitalsource.com/books/9781307917031
Kang, P. , Kang, J. & Monsen, K.A(2022).ANurse Information Security Policy Compliance,
Information Competence, and Information Security Attitudes Predict Information
Security Behavior.ACIN: Computers, Informatics, Nursing,Publish Ahead of Print,Adoi:
10.1097/CIN.0000000000000981.
Lee, D., Lallie, H.S. & Michaelides, N. The impact of an employee’s psychological contract
breach on compliance with information security policies: intrinsic and extrinsic
motivation.ACogn Tech WorkA25, 273–289 (2023). https://doi.org/10.1007/s10111-023-
00727-5
Mihai, T. (2018). Jesus Christ: Ethics Lessons for Project Managers. The Journal of Biblical
Integration in Business, 21(1), 81-92.
https://cbfa-jbib.org/index.php/jbib/article/view/495/503
Nifakos, S., Chandramouli, K., Nikolaou, C. K., Papachristou, P., Koch, S., Panaousis, E., &
Bonacina, S. (2021). Influence of Human Factors on Cyber Security within Healthcare
HUMAN COMPLIANCE 11
Organisations: A Systematic Review.ASensors (Basel, Switzerland),A21(15), 5119.
https://doi.org/10.3390/s21155119
Olukoya, O. (2022). Assessing frameworks for eliciting privacy & security requirements from
laws and regulations.Computers & Security,117,
102697.Ahttps://doi.org/10.1016/j.cose.2022.102697
Sarkar, S., Vance, A. (2020). The Influence of Professional Subculture on Information Security
Policy Violations: A Field Study in a Healthcase Context. Information Systems
Research, 31(4), 1037-1492. https://doi.org/10.1287/isre.2020.0941
Students also viewed