Awareness, Education, Training Flashcards
Disagvantages
Poor cost benefit trade off
Infeasible
Negative side effects
Reasons for not installing updates
-Unpleasant suprise UI changes
-unclear what should be updated
-unclear why an update is needed
Security awareness
Is a latent variable, cant be observed directly, no exact definition
Is user education generally a good idea?
-it may scare people off
-security is too complicated-user education does not work
-puts burden on the wrong shoulders
Processing the fear messages
1st appraisal: is the threat perceived as really threatening
-if no-no fear-nth happens
-if yes-fear-2nd appraisal
2nd appraisal- is the proposed response perceived as effective?
-if yes-danger control process-effective response
-if not-fear control process-non effective response
Information Privacy
Claim of individuals, groups or institutions to determine for themselves when, how and to what extent info about them is communicated to others
Privacy vs confidentiality
Confidentiality- controlled access-info only authorized by authorized entities-no perfect secrecy
Privacy-control where, what and how info about a person is made available-desire and right of control over disclosure. Not perfect secrecy
3 types of privacy
1.interpersonal privacy
2.consumer privacy
3.citizen privacy
Interpersonal privacy
Type of privacy. Privacy towards other known and unkown individuals such as family, friends, passersby’s…
Consumer privacy
Privacy towards commercial organizations and service oriented governmental organizations
Citizen privacy
Privacy towards governmental organizations concerned with safety and security of citizens
Charter of fundamental rights of the eu article 8-1
Everyone has the right to the protection of personal data concerning him and her
Personal data(gdpr definition)
Any data that can be connected to a concrete person, possibly with the help of additional info from other sources
Westin’s cluster
Privacy fundamentalists-extremely concerned about security-generally unwilling to provide data
Privacy pragmatic-concerned but less so, often specific concerns
Privacy unaware-generally wiling to provide data-often expressing a mild general concern
Privacy dichotomy/privacy paradox
Attitudes to privacy differ considerably from privacy-preserving behavior i.e. people are strongly concerned about privacy but release info for small rewards
I.e. loyalty cards-reports your purchases to interested third parties