KIT | KIT-Bibliothek | Impressum | Datenschutz

Encouraging Organisational Information Security Incident Reporting

Ballreich, Fabian Lucas ORCID iD icon 1; Volkamer, Melanie 1; Müllmann, Dirk 1; Berens, Benjamin Maximilian ORCID iD icon 1; Häußler, Elena Marie 2; Renaud, Karen V.
1 Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB), Karlsruher Institut für Technologie (KIT)
2 Karlsruher Institut für Technologie (KIT)

Abstract (englisch):

21𝑠𝑡 -century organisations can only learn how to respond effec- tively to, and recover from, adverse information security incidents if their employees report any incidents they notice. This should happen irrespective of whether or not they themselves triggered the incident. Organisations have started to inform their employ- ees about their incident reporting obligations. However, there is little research that organisations can benefit from to make their reporting provisions maximally effective. For this work, we follow a multi-step approach. (1) We review the related research on report- ing, including reporting reluctance, and the legalities of incident reporting in the European Union. (2) We explain how we developed variations of information texts that raise awareness of incident re- porting obligations and aim to ameliorate reporting reluctance. (3) We conducted an online user study (n=257) to identify the most ef- fective information text. (4) The most effective text was deployed by the CISO of a German energy company and we collected feedback from 24 employees to support a qualitative analysis. We discuss our experiences and the implications of such information text design. ... mehr


Preprint §
DOI: 10.5445/IR/1000163448
Veröffentlicht am 30.10.2023
Originalveröffentlichung
DOI: 10.1145/3617072.3617098
Scopus
Zitationen: 1
Dimensions
Zitationen: 1
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB)
Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Proceedingsbeitrag
Publikationsdatum 16.10.2023
Sprache Englisch
Identifikator ISBN: 979-8-4007-0814-5
KITopen-ID: 1000163448
HGF-Programm 46.23.01 (POF IV, LK 01) Methods for Engineering Secure Systems
Erschienen in EuroUSEC '23: Proceedings of the 2023 European Symposium on Usable Security
Veranstaltung European Workshop on Usable Security (EuroUSEC 2023), Kopenhagen, Dänemark, 16.10.2023 – 17.10.2023
Verlag Association for Computing Machinery (ACM)
Seiten 224–236
Schlagwörter Barriers to information security incident reporting; reporting reluctance, information security incidents, reporting obligation
Nachgewiesen in Dimensions
Scopus
KIT – Die Forschungsuniversität in der Helmholtz-Gemeinschaft
KITopen Landing Page