There are popular information security catchphrases that attempt to make a comparison between patching systems and patching people (or even patching stupidity). While it is certainly possible to implement strategies, systems, and techniques that can result in sudden changes to people’s habits, it is tempting to take the concept too far and see people as systems that can be “fixed” once and for all. But, people do not work that way. Patching software rewrites the underlying code of a system so that the system consistently behaves in a certain way. Getting people to want to change their habits, on the other hand, is a subtle process that works over time, and it is not an exact science.
KeywordsActive Feedback Exact Science Frequent Feedback Security Awareness Score Progress
- Aaron Dignan. Game Frame. Free Press, New York, NY, 2011.Google Scholar
- Abraham Maslow. Toward a Psychology of Being. Wiley and Sons, New York, NY, 3rd edition, 1998.Google Scholar
- Charles Coonradt. The Game of Work. Gibbs Smith, United States, 2012.Google Scholar
- Karen Pryor. Don’t Shoot the Dog! Bantam, San Francisco, USA, 1999.Google Scholar
- Ponnurangam Kumaraguru; Yong Rhee; Steve Sheng; Sharique Hasan; Alessandro Acquisti; Lorrie Cranor; Jason Hong. Getting users to pay attention to anti-phishing education: Evaluation of retention and transfer. Technical report, Carnegie Mellon University, 2007.Google Scholar