VLDB 2026 Research / reviewers in the wild / expert
Aggeliki Tsohou
dblp:00/6526
· DBLP profile ↗
23ranked-venue papers
11as first author
7since 2021 · last 2024
0000-0003-2200-3651ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 10 first-author · 6 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Exploring users' attitude towards privacy-preserving search engines: a protection motivation theory approachabstractPurpose Search engines, the most popular online services, are associated with several concerns. Users are concerned about the unauthorized processing of their personal data, as well as about search engines keeping track of their search preferences. Various search engines have been introduced to address these concerns, claiming that they protect users’ privacy. The authors call these search engines privacy-preserving search engines (PPSEs). This paper aims to investigate the factors that motivate search engine users to use PPSEs. Design/methodology/approach This study adopted protection motivation theory (PMT) and associated its constructs with subjective norms to build a comprehensive research model. The authors tested the research model using survey data from 830 search engine users worldwide. Findings The results confirm the interpretive power of PMT in privacy-related decision-making and show that users are more inclined to take protective measures when they consider that data abuse is a more severe risk and that they are more vulnerable to data abuse. Furthermore, the results highlight the importance of subjective norms in predicting and determining PPSE use. Because subjective norms refer to perceived social influences from important others to engage or refrain from protective behavior, the authors reveal that the recommendation from people that users consider important motivates them to take protective measures and use PPSE. Research limitations/implications Despite its interesting results, this research also has some limitations. First, because the survey was conducted online, the study environment was less controlled. Participants may have been disrupted or affected, for example, by the presence of others or background noise during the session. Second, some of the survey items could possibly be misinterpreted by the respondents in the study questionnaire, as they did not have access to clarifications that a researcher could possibly provide. Third, another limitation refers to the use of the Amazon Turk tool. According Paolacci and Chandler (2014) in comparison to the US population, the MTurk workers are more educated, younger and less religiously and politically diverse. Fourth, another limitation of this study could be that Actual Use of PPSE is self-reported by the participants. This could cause bias because it is argued that internet users’ statements may be in contrast with their actions in real life or in an experimental scenario (Berendt et al., 2005, Jensen et al., 2005); Moreover, some limitations of this study emerge from the use of PMT as the background theory of the study. PMT identifies the main factors that affect protection motivation, but other environmental and cognitive factors can also have a significant role in determining the way an individual’s attitude is formed. As Rogers (1975) argued, PMT as proposed does not attempt to specify all of the possible factors in a fear appeal that may affect persuasion, but rather a systematic exposition of a limited set of components and cognitive mediational processes that may account for a significant portion of the variance in acceptance by users. In addition, as Tanner et al. (1991) argue, the ‘PMT’s assumption that the subjects have not already developed a coping mechanism is one of its limitations. Finally, another limitation is that the sample does not include users from China, which is the second most populated country. Unfortunately, DuckDuckGo has been blocked in China, so it has not been feasible to include users from China in this study. Practical implications The proposed model and, specifically, the subjective norms construct proved to be successful in predicting PPSE use. This study demonstrates the need for PPSE to exhibit and advertise the technology and measures they use to protect users’ privacy. This will contribute to the effort to persuade internet users to use these tools. Social implications This study sought to explore the privacy attitudes of search engine users using PMT and its constructs’ association with subjective norms. It used the PMT to elucidate users’ perceptions that motivate them to privacy adoption behavior, as well as how these perceptions influence the type of search engine they use. This research is a first step toward gaining a better understanding of the processes that drive people’s motivation to, or not to, protect their privacy online by means of using PPSE. At the same time, this study contributes to search engine vendors by revealing that users’ need to be persuaded not only about their policy toward privacy but also by considering and implementing new strategies of diffusion that could enhance the use of the PPSE. Originality/value This research is a first step toward gaining a better understanding of the processes that drive people’s motivation to, or not to, protect their privacy online by means of using PPSEs. Andreas Skalkos, Aggeliki Tsohou, Maria Karyda 0001, Spyros Kokolakis |
Inf. Comput. Secur. | 2 |
| 2023 | Towards an Information Privacy Competency Model for the Usage of Mobile Applications
Aikaterini Soumelidou, Aggeliki Tsohou |
SEC | 2 |
| 2023 | Personal use of technology at work: a literature review and a theoretical model for understanding how it affects employee job performanceabstractEmployee personal use of technology at work (PUTW) – defined as employees’ activities using organisational or personal IT resources for non-work-related purposes while at work – is increasingly common. Our review of existing PUTW studies (n = 137) suggests that previous studies widely discussed PUTW outcomes, antecedents, and policies. The literature review also indicates that previous studies proposed opposing viewpoints regarding the effect of PUTW on employee job performance, but few studies offered empirical evidence. Consequently, the conditions under which PUTW can increase or decrease employee job performance have not been discussed. We develop a theoretical model for increasing the understanding of this issue. Our model suggests that executive attention is an important underlying mechanism through which PUTW affects employee job performance. We further suggest the effect of PUTW on executive attention (and job performance) depends on PUTW behavioural characteristics in terms of four dimensions: PUTW cognitive load, PUTW arousal level, PUTW timing, and PUTW frequency/duration. The model can advance researchers’ understanding of the possible conditions under which PUTW may increase or decrease employee job performance. The model also offers new insights into existing studies on PUTW antecedents and policies. As a result, our proposed model provides new theoretical guidance for future studies on PUTW. Hemin Jiang, Mikko Siponen, Aggeliki Tsohou |
Eur. J. Inf. Syst. | 3 |
| 2022 | Requirements for an Information Privacy Pedagogy based on the Constructivism Learning TheoryabstractThe protection of information privacy is a timely issue, as the penetration of the Internet overwhelms every aspect of individuals' lives. Internet users’ privacy knowledge is often low, potentially due to the lack of theoretically founded methods for awareness raising and education. To address this gap, we propose the design of privacy learning activities based on a widely accepted learning theory (i.e., constructivism) derived from the education science. Since there is no specific pedagogy that guides towards specific practices for the application of the constructivism learning theory, in this paper we discuss the principles of constructivism, and we develop a set of requirements towards this direction. We adopt these requirements in information privacy learning, and we present an indicative scenario about the way that each requirement can be adopted in an educational activity, in order to result in changes of individual's privacy attitudes and behaviors. Thanos Papaioannou, Aggeliki Tsohou, Maria Karyda 0001, Stylianos Karagiannis |
ARES | 2 |
| 2022 | A Constructive Approach for Raising Information Privacy Competences: The Case of Escape Room Games
Thanos Papaioannou, Aggeliki Tsohou, Georgios Bounias, Stylianos Karagiannis |
TrustBus | 2 |
| 2021 | Towards an Information Privacy and Personal Data Protection Competency Model for Citizens
Aggeliki Tsohou |
TrustBus | 1 |
| 2021 | Forming digital identities in social networks: the role of privacy concerns and self-esteemabstractPurpose This paper aims to identify the data elements that social network sites (SNS) users consider important for shaping their digital identity and explore how users’ privacy concerns, self-esteem and the chosen SNS shape this process. Design/methodology/approach This study conducted an online survey with the participation of 759 individuals, to examine the influence of privacy concerns, self-esteem and the chosen SNS platform, on the shaping of the digital identity, through a classification of identity elements that users disclose when using a SNS, the Rosenberg self-esteem scale and relevant constructs from the literature. Findings Findings reveal that users consider the name, gender, picture, interests and job as most important elements for shaping their digital identity. They also demonstrate that privacy concerns do not seem to affect the amount of information users choose to publish when shaping their digital identity. Specific characteristics of SNS platforms are found to affect the way that users shape their digital identity and their privacy behavior. Finally, self-esteem was found to affect privacy concerns and digital identity formation. Research limitations/implications To avoid a lengthy questionnaire and the risk of low participation, the respondents answered the questions for one SNS of their choice instead of answering the full questionnaire for each SNS that they use. The survey included the most popular SNSs at the time of the survey in terms of popularity. Practical implications The results contribute to the theory by furthering our knowledge on the elements that shape digital identity and by providing evidence with regard to the role of privacy and self-esteem within social networking. In practice, they can be useful for SNS providers, as well as for entities that design security and privacy awareness campaigns. Originality/value This paper identifies novel factors that influence digital identity formation, including the specific SNS used with its particular characteristics in combination with privacy concerns and self-esteem of the user. Thanos Papaioannou, Aggeliki Tsohou, Maria Karyda 0001 |
Inf. Comput. Secur. | 2 |
| 2020 | DEFeND DSM: A Data Scope Management Service for Model-Based Privacy by Design GDPR Compliance
Luca Piras 0003, Mohammed Al-Obeidallah, Michalis Pavlidis, Haralambos Mouratidis, Aggeliki Tsohou, Emmanouil Magkos, Andrea Praitano, Annarita Iodice, Beatriz Gallego-Nicasio |
TrustBus | 5 |
| 2020 | From ISO/IEC27001: 2013 and ISO/IEC27002: 2013 to GDPR compliance controlsabstractPurpose This paper aims to identify the controls provisioned in ISO/IEC 27001:2013 and ISO/IEC 27002:2013 that need to be extended to adequately meet, data protection requirements set by the General Data Protection Regulation (GDPR); it also indicates security management actions an organisation needs to perform to fulfil GDPR requirements. Thus, ISO/IEC 27001:2013 compliant organisations, can use this paper as a basis for extending the already existing security control modules towards data protection; and as guidance for reaching compliance with the regulation. Design/methodology/approach This study has followed a two-step approach; first, synergies between ISO/IEC 27001:2013 modules and GDPR requirements were identified, by analysing all 14 control modules of the ISO/IEC 27001:2013 and proposing the appropriate actions towards the satisfaction of data protection requirements. Second, this paper identified GDPR requirements not addressed by ISO/IEC 27001:2013. Findings The findings of this work include the identification of the common ground between the security controls that ISO/IEC 27001:2013 includes and the requirements that the GDPR imposes; the actions that need to be performed based on these security controls to adequately meet the data protection requirements that the GDPR imposes; and the identification of the remaining actions an ISO/IEC 27001 compliant organisation needs to perform to be able to adhere with the GDPR. Originality/value This paper provides a gap analysis and a further steps identification regarding the additional actions that need to be performed to allow an ISO/IEC 27001:2013 certified organisation to be compliant with the GDPR. Vasiliki Diamantopoulou, Aggeliki Tsohou, Maria Karyda 0001 |
Inf. Comput. Secur. | 2 |
| 2020 | AppAware: a policy visualization model for mobile applicationsabstractPurpose Privacy policies emerge as the main mechanism to inform users on the way their information is managed by online service providers, and still remain the dominant approach for this purpose. The literature notes that users find difficulties in understanding privacy policies because they are usually written in technical or legal language even, although most users are unfamiliar with them. These difficulties have led most users to skip reading privacy policies and blindly accept them. This study aims to address this challenge this paper presents AppAware, a multiplatform tool that intends to improve the visualization of privacy policies for mobile applications. Design/methodology/approach AppAware formulates a visualized report with the permission set of an application, which is easily understandable by a common user. AppAware aims to bridge the difficulty to read privacy policies and android’s obscure permission set with a new privacy policy visualization model. Thus, we propose AppAware parser, a mobile add-on that acts complementary with AppAware and helps mobile device users to monitor the applications they installed to their smart device. Findings To validate AppAware, the authors conducted a survey through questionnaire aiming to evaluate AppAware in terms of installability, usability and viability-purpose. The results demonstrate that AppAware is assessed above average by the users in all categories. Originality/value In the best of the authors’ knowledge, there is no such approach as AppAware as an application nor AppAware parser as add-on. Ioannis Paspatis, Aggeliki Tsohou, Spyros Kokolakis |
Inf. Comput. Secur. | 2 |
| 2020 | Privacy, security, legal and technology acceptance elicited and consolidated requirements for a GDPR compliance platformabstractPurpose General data protection regulation (GDPR) entered into force in May 2018 for enhancing personal data protection. Even though GDPR leads toward many advantages for the data subjects it turned out to be a significant challenge. Organizations need to implement long and complex changes to become GDPR compliant. Data subjects are empowered with new rights, which, however, they need to become aware of. GDPR compliance is a challenging matter for the relevant stakeholders calls for a software platform that can support their needs. The aim of data governance for supporting GDPR (DEFeND) EU project is to deliver such a platform. The purpose of this paper is to describe the process, within the DEFeND EU project, for eliciting and analyzing requirements for such a complex platform. Design/methodology/approach The platform needs to satisfy legal and privacy requirements and provide functionalities that data controllers request for supporting GDPR compliance. Further, it needs to satisfy acceptance requirements, for assuring that its users will embrace and use the platform. In this paper, the authors describe the methodology for eliciting and analyzing requirements for such a complex platform, by analyzing data attained by stakeholders from different sectors. Findings The findings provide the process for the DEFeND platform requirements’ elicitation and an indicative sample of those. The authors also describe the implementation of a secondary process for consolidating the elicited requirements into a consistent set of platform requirements. Practical implications The proposed software engineering methodology and data collection tools (i.e. questionnaires) are expected to have a significant impact for software engineers in academia and industry. Social implications It is reported repeatedly that data controllers face difficulties in complying with the GDPR. The study aims to offer mechanisms and tools that can assist organizations to comply with the GDPR, thus, offering a significant boost toward the European personal data protection objectives. Originality/value This is the first paper, according to the best of the authors’ knowledge, to provide software requirements for a GDPR compliance platform, including multiple perspectives. Aggeliki Tsohou, Emmanouil Magkos, Haralambos Mouratidis, George Chrysoloras, Luca Piras 0003, Michalis Pavlidis, Julien Debussche, Marco Rotoloni, Beatriz Gallego-Nicasio |
Inf. Comput. Secur. | 1 |
| 2019 | General Data Protection Regulation and ISO/IEC 27001: 2013: Synergies of Activities Towards Organisations' Compliance
Vasiliki Diamantopoulou, Aggeliki Tsohou, Maria Karyda 0001 |
TrustBus | 2 |
| 2019 | DEFeND Architecture: A Privacy by Design Platform for GDPR Compliance
Luca Piras 0003, Mohammed Al-Obeidallah, Andrea Praitano, Aggeliki Tsohou, Haralambos Mouratidis, Beatriz Gallego-Nicasio, Jean Baptiste Bernard, Marco Fiorani, Emmanouil Magkos, Andrès Castillo Sanz, Michalis Pavlidis, Roberto D'Addario, Giuseppe Giovanni Zorzino |
TrustBus | 4 |
| 2019 | Developing and validating a common body of knowledge for information privacyabstractPurpose This paper aims to present a common body of knowledge (CBK) for the field of information privacy, titled InfoPrivacy CBK. The purpose of the proposed CBK is to guide internet users to better understand the concept of information privacy and associate information privacy-related concepts. The InfoPrivacy CBK was created with an educational orientation to provide the basis for designing privacy awareness and training programs and organizing relevant educational material. Design/methodology/approach The proposed CBK for information privacy was developed conceptually and includes five domains and four levels of analysis. It is illustrated with conceptual maps. The authors identified a variety of concepts related to information privacy and created a set of categories to categorize the concepts. They used, as inclusion criteria, both theoretical and practical information privacy aspects, so that the developed CBK can address the challenges of modern technologies for preserving information privacy. Findings To validate and refine the conceptually developed CBK, the authors conducted an empirical research, in which seven information privacy experts participated. The experts commented largely positively for the structure and content of InfoPrivacy CBK, as well as for the extent to which it achieves the intended educational goals. Research limitations/implications The proposed InfoPrivacy CBK was validated by a limited number of information privacy experts, mainly due to the lengthy and in-depth participation that was required. Practical implications The InfoPrivacy CBK can be used primarily by privacy awareness and training programs developers, such as organizations, data protection officers, the state, educational policy makers and teachers. Social implications Internet users will benefit from InfoPrivacy CBK by acquiring knowledge and skills from theoretically grounded training programs, which can enhance their awareness and critical thinking on issues related to the protection of their information privacy. This will lead to more privacy-aware online societies, communities, networks, etc. Originality/value This work intends to bridge the existing gap in the literature through the creation of a novel CBK for information privacy; information privacy is a field for which no such research effort has been recorded. This paper offers important knowledge in the field of information privacy, which could be useful to both technological education designers and learners (students, employees, etc.). Rena Lavranou, Aggeliki Tsohou |
Inf. Comput. Secur. | 2 |
| 2017 | Enabling valid informed consent for location tracking through privacy awareness of users: A process theory
Aggeliki Tsohou, Eleni Kosta |
Comput. Law Secur. Rev. | 1 |
| 2015 | Analyzing the role of cognitive and cultural biases in the internalization of information security policies: Recommendations for information security awareness programs
Aggeliki Tsohou, Maria Karyda 0001, Spyros Kokolakis |
Comput. Secur. | 1 |
| 2015 | Managing the introduction of information security awareness programmes in organisationsabstractSeveral studies explore information security awareness focusing on individual and/or organisational aspects. This paper argues that security awareness processes are associated with interrelated changes that occur at the organisational, the technological and the individual level. We introduce an integrated analytical framework that has been developed through action research in a public sector organisation, comprising actor-network theory (ANT), structuration theory and contextualism. We develop and use this framework to analyse and manage changes introduced by the implementation of a security awareness programme in the research setting. The paper illustrates the limitations of each theory (ANT, structuration theory and contextualism) to study multi-level changes when used individually, demonstrates the synergies of the three theories, and proposes how they can be used to study and manage awareness-related changes at the individual, organisational and technological level. Aggeliki Tsohou, Maria Karyda 0001, Spyros Kokolakis, Evangelos A. Kiountouzis |
Eur. J. Inf. Syst. | 1 |
| 2012 | Ubiquitous Participation Platform for POLicy Making (UbiPOL): Security and Identity Management Considerations
Aggeliki Tsohou, Habin Lee, Yacine Rebahi, Mateusz Khalil, Simon Hohberg |
TrustBus | 1 |
| 2010 | Analyzing Information Security Awareness through Networks of Association
Aggeliki Tsohou, Maria Karyda 0001, Spyros Kokolakis, Evangelos A. Kiountouzis |
TrustBus | 1 |
| 2010 | A Security Standards' Framework to Facilitate Best Practices' Awareness and ConformityabstractPurpose – Recent information security surveys indicate that both the acceptance of international standards and the relative certifications increase continuously. However, it is noted that still the majority of organizations does not know the dominant security standards or does not fully implement them. The aim of this paper is to facilitate the awareness of information security practitioners regarding globally known and accepted security standards, and thus, contribute to their adoption. Aggeliki Tsohou |
Inf. Manag. Comput. Secur. | 1 |
| 2008 | Process-variance models in information security awareness researchabstractPurpose The purpose of this paper is to study the way information systems (IS) security researchers approach information security awareness and examine whether these approaches are consistent with the organization theory and IS approaches for the study of organizational processes. Design/methodology/approach Open coding analysis was performed on selected publications (articles, surveys, standards, and reports). The chosen publications were classified and the classification results are presented, based on a proposed typology. Findings The proposed typology allows us to identify different types of research models followed by security researchers and practitioners, and to infer a set of practical implications, for the benefit of those interested in empirically studying information security awareness. Research limitations/implications The paper represents a pilot survey, performed in a selected number of publications. Practical implications The paper helps researchers and practitioners to distinguish the research models that can be adopted for the study of information security awareness organizational process, by identifying the key dimensions along which they differ. Originality/value The proposed typology provides a guide to identify the range of options available to researchers and practitioners when they design their work regarding the security awareness topic. Moreover, it can facilitate the communication between scholars in the field of security awareness. Aggeliki Tsohou, Spyros Kokolakis, Maria Karyda 0001, Evangelos A. Kiountouzis |
Inf. Manag. Comput. Secur. | 1 |
| 2007 | Addressing Cultural Dissimilarity in the Information Security Management Outsourcing Relationship
Aggeliki Tsohou, Marianthi Theoharidou, Spyros Kokolakis, Dimitris Gritzalis |
TrustBus | 1 |
| 2006 | Formulating information systems risk management strategies through cultural theoryabstractPurpose The purpose of this paper is to examine the potential of cultural theory as a tool for identifying patterns in the stakeholders' perception of risk and its effect on information system (IS) risk management. Design/methodology/approach Risk management involves a number of human activities which are based on the way the various stakeholders perceive risk associated with IS assets. Cultural theory claims that risk perception within social groups and structures is predictable according to group and individual worldviews; therefore this paper examines the implications of cultural theory on IS risk management as a means for security experts to manage stakeholders perceptions. Findings A basic theoretical element of cultural theory is the grid/group typology, where four cultural groups with differentiating worldviews are identified. This paper presents how these worldviews affect the process of IS risk management and suggests key issues to be considered in developing strategies of risk management according to the different perceptions cultural groups have. Research limitations/implications The findings of this research are based on theoretical analysis and are not supported by relevant empirical research. Further research is also required for incorporating the identified key issues into information security management systems (ISMS). Originality/value IS security management overlooks stakeholders' risk perception; for example, there is no scheme developed to understand and manage the perception of IS stakeholders. This paper proposes some key issues that should be taken into account when developing strategies for addressing the issue of understanding and managing the perception of IS stakeholders. Aggeliki Tsohou, Maria Karyda 0001, Spyros Kokolakis, Evangelos A. Kiountouzis |
Inf. Manag. Comput. Secur. | 1 |