User Resistance to Password Security Explored

Though most organizations have policies and guidelines to protect their information systems from unauthorized access, research has shown that employee compliance is often a problem.

“Even if the policies are mandatory, individual perceptions, interpretations, and behavior vary within the process of complying,” said France Belanger, Pamplin College of Business accounting and information systems professor at Virginia Tech.

Belanger and three Pamplin doctoral students completed a new study exploring the attitudes and “resistance behavior” of individuals faced with a required information technology security change. Previous studies, she said, largely focused on voluntary behavior.

Using Virginia Tech as a case study, Belanger and her team — Eric Negangard and Kathy Enget (accounting and information systems) and Stephane Collignon (business information technology) — surveyed undergraduate and graduate students, faculty members, staff, and administrators at Virginia Tech. The university required its information systems account holders to change their passwords by July 1, 2011, after evaluating password practices in the wake of recurring security problems. Accounts would not be accessible with old passwords after the deadline.

Managers who develop and implement information security procedures may find some useful lessons about change management in the study, Belanger said. It highlights the role of user awareness of the security change in influencing user attitudes toward the change and shows the relative importance of various organizational measures to publicize the change.

Featured

New Products

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions.

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.