Bag om Designing a Messaging Strategy to Improve Information Security Policy
Lack of employee compliance with information security policies is a key factor driving security incidents. Information security practitioners struggle to enforce policy compliance while employees try to curtail safeguards in favor of expediency and other perceived business goals. Several studies have shown individual and organizational factors influencing this type of employee behavior. However, few have recommended management-level interventions that can be used as a solution framework by information security practitioners. This research utilized the Design Science Research (DSR) methodology to develop a management-level intervention based on a messaging strategy that aims to help information security practitioners improve the information security culture of their organization through employees¿ intrinsic motivation, thus increasing compliance with information security policies. DSR calls for the design of an artifact to solve a problem of practice. In this research, the artifact is the management-level intervention mentioned above.
Vis mere