Skip to search boxSkip to navigationSkip to main content

Machine Learning and Survey-based Predictors of InfoSec Non-Compliance

  • Byron Marshall
    ,
  • Michael Curry
    ,
  • Robert E. Crossler
    ,
Research Output:
Contribution to journal
Article
Peer-review

Open access

Publication metrics

PlumX, opens in new tab

Citations
2
Captures
56
Social media
1

Abstract

Survey items developed in behavioral Information Security (InfoSec) research should be practically useful in identifying individuals who are likely to create risk by failing to comply with InfoSec guidance. The literature shows that attitudes, beliefs, and perceptions drive compliance behavior and has influenced the creation of a multitude of training programs focused on improving ones' InfoSec behaviors. While automated controls and directly observable technical indicators are generally preferred by InfoSec practitioners, difficult-to-monitor user actions can still compromise the effectiveness of automatic controls. For example, despite prohibition, doubtful or skeptical employees often increase organizational risk by using the same password to authenticate corporate and external services. Analysis of network traffic or device configurations is unlikely to provide evidence of these vulnerabilities but responses to well-designed surveys might. Guided by the relatively new IPAM model, this study administered 96 survey items from the Behavioral InfoSec literature, across three separate points in time, to 217 respondents. Using systematic feature selection techniques, manageable subsets of 29, 20, and 15 items were identified and tested as predictors of non-compliance with security policy. The feature selection process validates IPAM's innovation in using nuanced self-efficacy and planning items across multiple time frames. Prediction models were trained using several ML algorithms. Practically useful levels of prediction accuracy were achieved with, for example, ensemble tree models identifying 69% of the riskiest individuals within the top 25% of the sample. The findings indicate the usefulness of psychometric items from the behavioral InfoSec in guiding training programs and other cybersecurity control activities and demonstrate that they are promising as additional inputs to AI models that monitor networks for security events.

Bibliographic Information

Output type

Research Output:
Contribution to journal
Article
Peer-review

Original language

English

Article number

13

Journal (Volume, Issue Number)

ACM Transactions on Management Information Systems (Volume 13, Issue 2)

Publication milestones

  • Published - 06/2022

Publication status

Published - 06/2022

ISSN

2158-656X

Publication IDs

  • Scopus: 85127612080