The cost of non-compliance: when policies fail

  • Authors:
  • Elinor M. Madigan;Corey Petrulich;Kelly Motuk

  • Affiliations:
  • Penn State University, Schuylkill Haven;Penn State University, Schuylkill Haven;Penn State University, Schuylkill Haven

  • Venue:
  • SIGUCCS '04 Proceedings of the 32nd annual ACM SIGUCCS conference on User services
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

Employees are the greatest threat to an organization's security. Their non-compliance with security policies not only threatens the integrity of the system, it also costs the organization a significant amount of money due to the loss of information or the man-hours spent fixing problems that the user causes. This paper looks at the man-hour cost due to non-compliance at a branch of a large university. We identified what constituted non-compliance and then had the IT staff track the number of hours they spent addressing these problems over a 13-month period. This paper also covers what actions and tools the IT department is using to combat the problem of user non-compliance.