Obligations to enforce prohibitions: on the adequacy of security policies

@inproceedings{Pieters2013ObligationsTE,
  title={Obligations to enforce prohibitions: on the adequacy of security policies},
  author={Wolter Pieters and Julian Padget and Francien Dechesne and Virginia Dignum and Huib Aldewereld},
  booktitle={SIN},
  year={2013}
}
Security policies in organisations typically take the form of obligations for the employees. However, it is often unclear what the purpose of such obligations is, and how these can be integrated in the operational processes of the organisation. This can result in policies that may be either too strong or too weak, leading to unnecessary productivity loss, or the possibility of becoming victim to attacks that exploit the weaknesses, respectively. In this paper, we propose a framework in which… CONTINUE READING