The Role of Heuristics and Biases in Linux Server Administrators’ Information Security Policy Compliance at Healthcare Organizations

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Information Security Policy (ISP) compliance is crucial to healthcare organizations due to the potential for data breaches. The healthcare industry relies heavily on Linux servers to house electronically Protected Health Information (ePHI) due to their inherited lower volume of known vulnerabilities. However, Linux Server Administrators appear to be more relaxed than other server administrators when it comes to ISP compliance. Prior research suggests that the use of cognitive heuristics and biases may negatively influence threat appraisal and coping appraisal, while ultimately impacting ISP compliance. Thus, the goal of our study was to empirically assess the effect of cognitive heuristics, biases, and knowledge-sharing level on actual ISP compliance measured based on actual security setting adjustments. Aside from the novel measure of actual ISP compliance, we developed a survey instrument based on prior validated instruments to measure cognitive heuristics and biases. A group of 42 Linux Server Administrators who oversee the servers at a major healthcare organization participated in our study. Additionally, an intervention in the form of hands-on cybersecurity training, periodic security update emails, and Linux-focused tabletop exercises was introduced. Our results indicated that information security knowledge-sharing significantly influenced both cognitive heuristics and biases. Conclusions and discussions are provided.

Original languageEnglish
Title of host publicationProceedings of the 10th International Conference on Information Systems Security and Privacy
EditorsGabriele Lenzini, Paolo Mori, Steven Furnell
PublisherScience and Technology Publications, Lda
Pages30-41
Number of pages12
ISBN (Print)9789897586835
DOIs
StatePublished - 2024
Event10th International Conference on Information Systems Security and Privacy, ICISSP 2024 - Rome, Italy
Duration: Feb 26 2024Feb 28 2024

Publication series

NameProceedings of the 10th International Conference on Information Systems Security and Privacy

Conference

Conference10th International Conference on Information Systems Security and Privacy, ICISSP 2024
Country/TerritoryItaly
CityRome
Period2/26/242/28/24

Bibliographical note

Publisher Copyright:
© 2024 by SCITEPRESS – Science and Technology Publications, Lda.

ASJC Scopus Subject Areas

  • Computer Science (miscellaneous)
  • Information Systems

Keywords

  • Cognitive Biases
  • Cognitive Heuristics
  • Healthcare Cybersecurity
  • Information Security Policy Compliance
  • Linux Server Administrators

Disciplines

  • Computer Engineering

Fingerprint

Dive into the research topics of 'The Role of Heuristics and Biases in Linux Server Administrators’ Information Security Policy Compliance at Healthcare Organizations'. Together they form a unique fingerprint.

Cite this