Dirk Snyman

dblp:181/7331 · also Dirk P. Snyman, Dirk Petrus Snyman · DBLP profile ↗
← Back
8ranked-venue papers
7as first author
3since 2021 · last 2023
0000-0001-7360-3214ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 6 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
YearPublicationVenuePosition
2023 The Story of Safety Snail and Her e-Mail: A Digital Wellness and Cybersecurity Serious Game for Pre-School Children
Günther Drevin, Dirk Snyman, Lynette Drevin, Hennie A. Kruger, Johann Allers
ICISSP2
2022 The Role of Information Deserts in Information Security Awareness and Behaviour
Dirk Snyman, Hennie A. Kruger
ICISSP1
2021 Collective information security behaviour: a technology-driven framework
abstract
Purpose This paper aims to present the development of a framework for evaluating group behaviour in information security in practice. Design/methodology/approach Information security behavioural threshold analysis is used as the theoretical foundation for the proposed framework. The suitability of the proposed framework is evaluated based on two sets of qualitative measures (general frameworks and information security frameworks) which were identified from literature. The successful evaluation of the proposed framework, guided by the identified evaluation measures, is presented in terms of positive practical applications, as well as positive peer review and publication of the underlying theory. Findings A methodology to formalise a framework to analyse group behaviour in information security can successfully be applied in a practical environment. This application takes the framework from only a theoretical conceptualisation to an implementable solution to evaluate and positively influence information security group behaviour. Practical implications Behavioural threshold analysis is identified as a practical mechanism to evaluate information security group behaviour. The suggested framework, as implemented in a management decision support system (DSS), allows practitioners to assess the security behaviour and awareness in their organisation. The resulting information can be used to exert an influence for positive change in the information security of the organisation. Originality/value A novel conceptual mapping of two sets of qualitative evaluation measures is presented and used to evaluate the proposed framework. The resulting framework is made practical through its encapsulation in a DSS.
Dirk Snyman, Hennie A. Kruger
Inf. Comput. Secur.1
2020 External Contextual Factors in Information Security Behaviour
abstract
Human behaviour is often considered to be irrational, difficult to understand, and challenging to manage. This \nphenomenon has a direct impact on the way in which humans behave when confronted with information \nsecurity which, in turn, complicates how security is to be managed. This research attempts to investigate the \nrole that contextual factors play in how humans behave, specifically with regards to information security. \nContextual factors are identified that influence human behaviour in general. These factors are conceptualised \nin relation to existing models of behaviour and subsequently mapped to information security behaviour. A \npractical research exercise, relating to information security behaviour, is conducted with a university \nresidence as the contextual environment. The specific contextual factors, and how they relate to information \nsecurity, are discussed. Information security behavioural threshold analysis is employed to evaluate the impact \nof the identified contextual factors on the residence’s security behaviour. The results are reflected upon, based \non the results from the threshold analysis. The paper concludes by highlighting the contributions that were \nmade towards understanding contextual factors in information security
Dirk Snyman, Hennie A. Kruger
ICISSP1
2019 Theorising on Information Cascades and Sequential Decision-making for Analysing Security Behaviour
abstract
Human behaviour is an ever-present aspect in information security and requires special attention when seeking to secure information systems. Information security behaviour is often based on an informed decision where information is obtained by previous experience and observation of the behaviour of others. In this research, the concept of sequential decision-making is contextualised in terms of information security behaviour. Information cascades, which are based on sequential decision-making, are theorised as a model to explain how decision-making (i.e. behaviour) takes place in terms of information security. A case study is presented to illustrate how behavioural threshold analysis can be employed as an instrument to evaluate the effect of information cascades and sequential decision-making on information security behaviour. The paper concludes by theorising on the applicability of the models and approaches that are presented in this research
Dirk Snyman, Hennie A. Kruger
ICISSP1
2019 Behavioural threshold analysis: methodological and practical considerations for applications in information security
abstract
The application of behavioural threshold analysis to analyse group behaviour in information security presents a unique challenge in terms of the measurement instruments and methodology used to gather relevant attitude data. This paper presents an analysis of the specialised requirements for such a measurement instrument and makes methodological recommendations on the content and especially presentation of information security topics in a measurement instrument for this context. A comparison between existing methods and the specific requirements for threshold analysis is presented and serves as the main rationale for the suggested methodology. The recommended methodology and subsequent measurement instrument were implemented and experimentally tested in case studies to gauge their feasibility. Applications of behavioural threshold analysis in information security that follow the recommended methodology suggested in this article performed satisfactorily and elicits cause for further real-world experimentation.
Dirk Snyman, Hennie A. Kruger
Behav. Inf. Technol.1
2018 I shall, we shall, and all others will: paradoxical information security behaviour
abstract
Purpose The purpose of this paper is to investigate the lemming effect as a possible cause for the privacy paradox in information security. Design/methodology/approach Behavioural threshold analysis is used to test for the presence of the lemming effect in information security behaviour. Paradoxical behaviour may be caused by the influential nature of the lemming effect. The lemming effect is presented as a possible cause of the privacy paradox. Findings The behavioural threshold analysis indicates that the lemming effect is indeed present in information security behaviour and may lead to paradoxical information security behaviour. Practical implications The analysis of the lemming effect can be used to assist companies in understanding the way employees influence each other in their behaviour in terms of security. By identifying possible problem areas, this approach can also assist in directing their information security education endeavours towards the most relevant topics. Originality/value This research describes the first investigation of the lemming effect in information security by means of behavioural threshold analysis in practice.
Dirk Snyman, Hennie A. Kruger, Wayne D. Kearney
Inf. Comput. Secur.1
2017 The application of behavioural thresholds to analyse collective behaviour in information security
abstract
Purpose The purpose of this study is to perform an exploratory investigation into the feasibility of behavioural threshold analysis as a possible aid in security awareness campaigns. Design/methodology/approach Generic behavioural threshold analysis is presented and then applied in the domain of information security by collecting data on the behavioural thresholds of individuals in a group setting and how the individuals influence each other when it comes to security behaviour. Findings Initial experimental results show that behavioural threshold analysis is feasible in the context of information security and may provide useful guidelines on how to construct information security awareness programmes. Practical implications Threshold analysis may contribute in a number of ways to information security, e.g. identification of security issues that are susceptible to peer pressure and easily influenced by peer behaviour; serve as a countermeasure against security fatigue; contribute to the economics of information security awareness programmes; track progress of security awareness campaigns; and provide a new measure for determining the importance of security awareness issues. Originality/value This paper describes the very first experiment to test the behavioural threshold analysis concepts in the context of information security.
Dirk Snyman, Hennie A. Kruger
Inf. Comput. Secur.1