The Visible Employee: Using Workplace Monitoring and Surveillance to Protect Information Assets--Without Compromising Employee Privacy or Tr: Using ... Compromising Employee Privacy or Trust - Softcover

Stanton, Jeffrey M.; Stam, Kathryn R.

 
9780910965743: The Visible Employee: Using Workplace Monitoring and Surveillance to Protect Information Assets--Without Compromising Employee Privacy or Tr: Using ... Compromising Employee Privacy or Trust

Inhaltsangabe

For business owners, managers, and IT staff interested in learning how to effectively and ethically monitor and influence workplace behavior, this guide is a roadmap to ensuring security without risking employee privacy or trust. The misuse of information systems by wired workers—either through error or by intent—is discussed in detail, as are possible results such as leaked or corrupted data, crippled networks, lost productivity, legal problems, or public embarrassment. This analysis of an extensive four-year research project conducted by the authors covers not only a range of security solutions for at-risk organizations but also the perceptions and attitudes of employees toward workplace surveillance.

Die Inhaltsangabe kann sich auf eine andere Ausgabe dieses Titels beziehen.

Über die Autorin bzw. den Autor

Jeffrey M. Stanton is an associate professor in the school of information studies at Syracuse University. His work has been published in Human Performance, International Journal of Human-Computer Interaction, Information Technology and People, Journal of Applied Psychology, Journal of Information Systems Education, and Personnel Psychology. He is the recipient of the National Science Foundation's CAREER award. He lives in Jamesville, New York. Kathryn R. Stam is an assistant professor of anthropology at the SUNY Institute of Technology–Utica. She is a founding member and the associate director of the Syracuse Information Security Evaluation (SISE) project. Her research has appeared in Journal of Digital Information, Journal of Information Systems Education, and World Health Forum. She lives in New Hartford, New York.

Auszug. © Genehmigter Nachdruck. Alle Rechte vorbehalten.

The Visible Employee

Using Workplace Monitoring and Surveillance to Protect Information Assets — Without Compromising Employee Privacy or Trust

By Jeffrey M. Stanton, Kathryn R. Stam

Information Today, Inc.

Copyright © 2006 Jeffrey M. Stanton and Kathryn R. Stam
All rights reserved.
ISBN: 978-0-910965-74-3

Contents

Copyright,
Foreword, by Gurpreet Dhillon,
Acknowledgments,
Preface,
CHAPTER 1 An Introduction to Information Protection and Employee Behavior,
CHAPTER 2 How Employees Affect Information Security,
CHAPTER 3 Information Security Technologies and Operations,
CHAPTER 4 Employee Monitoring, Surveillance, and Privacy,
CHAPTER 5 Managerial Perspectives,
CHAPTER 6 Information Technology Professionals' Perspectives,
CHAPTER 7 Employee Perspectives on Information Security and Privacy,
CHAPTER 8 Overall Analysis and Interpretation,
CHAPTER 9 Recommendations for Managers, Employees, and Information Security Professionals,
References,
Appendix A: Recommended Reading,
Appendix B: Discussion Questions,
Appendix C: Employee Security-Related Behavior List,
Appendix D: Leadership Interview Protocol,
Appendix E: Information Security Professional Interview Protocol,
Appendix F: Employee Interview Protocol,
Appendix G: Straightforward Acceptable Use Policy,
Appendix H: Straightforward Password Policy,
About the Authors,
Index,


CHAPTER 1

An Introduction to Information Protection and Employee Behavior


In most organizations, information flows at the heart of workplace activities. The effective management of information requires information technology, and that technology is therefore crucial to organizational success. Information technology comes in many forms — networked personal computers, personal productivity devices, software applications, the Internet, and more — but one thing all types of information technology have in common is that their effective use depends upon human users. People put the technology to work in managing information, and people are ultimately responsible for whether information technology succeeds or fails. Within organizations, these people are the employees who use the technology to get their jobs done, serve the needs of customers, and keep the organization running.

Almost all organizations that use information technology in any substantial way are also struggling to maintain effective information security. In an increasing number of organizations, information is among the most valuable assets they possess. As connectivity among information systems has increased, so has the likelihood of intrusion into the systems, thefts of business information, fraudulent use of information, defacement of organizational Web sites, and other forms of information loss or damage. A worldwide army of hackers, virus writers, and scam artists stands poised to inflict as much damage as possible on the Internet-connected organization. Organizations are always vulnerable to these external security threats to some degree, but industry research by Ernst and Young (2002) suggests that many expensive security breaches in fact result from activity that occurs within organizations: the so-called insider threat posed by employees or contractors who possess trusted access to the company's information and technology. At the low end, losses from security breaches of all types have been estimated at approximately $20 billion per year (counting U.S. organizations only; Security Wire Digest, 2000). Such losses cause organizations to open their wallets: According to a 2002 industry survey by Information Security magazine, very large organizations spend an average of $6 million per year on information security measures; smaller ones spend nearly 20 percent of their overall information technology budgets on security.

Among the various security technologies used in organizations, many provide the means to monitor employee behavior. Organizations deploy these complex and expensive monitoring technologies under the belief that secure management of an organization's information assets depends in part upon the behavior of employees. Employees are the "end-users" of much of the organization's information, and that information is very literally at their disposal. When employees are careful to handle information in a secure way, the organization, its customers, and its shareholders benefit from the protection of this key asset. Alternatively, mismanagement of information or the malfeasance of isolated individuals who "go bad" may have devastating effects on the organization's success.

Organizations possess an increasingly powerful technological toolbox for finding out what people are doing on their computers and on the network. For the many employees who use computers, a detailed electronic trail of communications, software utilization, and network activity now fills the log files of company servers. Almost every organization with business processes that connect it to the Internet uses one type of system or another to assess networked computer usage, track network access, warn about inappropriate behavior on the network, or try to ensure that such behavior cannot occur. Software and hardware vendors provide a huge array of options for collecting, storing, analyzing, and generating reports based on telecommunications records, logs of Web usage, addresses of e-mail recipients, and e-mail message content. A plethora of details about employees' work habits, computer usage, and personal demographics, and a wide range of other potentially sensitive information is collected and stored in organizational information systems. Enterprise computing systems contain centralized work records and other information about job -related activities in huge interlinked databases. Camera surveillance has also become increasingly common, particularly in the public spaces of the organization (e.g., lobbies, parking lots, customer areas of retail stores), but additionally in non-public spaces such as employee break rooms. Smart cards and proximity badges help the organization know where employees are located and what facilities they have used. All of these forms of monitoring and surveillance allow organizations to increase the visibility of employee behavior, analyze typical usage patterns, flag unusual or unauthorized activities, and reduce the lag between the discovery of problems and subsequent action or decision making. Monitoring and surveillance technologies seem to provide a panacea of observation, analysis, prediction, and control for those who wish to reduce the uncertainty, unpredictability, and risks related to the behavior of information systems users.

A series of U.S. industry surveys has shown that employee monitoring and surveillance occur to some degree in the majority of U.S. work organizations (9 to 5, 1990; Orthmann, 1998; Society for Human Resource Management, 1991, 1999, 2001). In their 2004 survey on workplace e-mail and instant messaging, the American Management Association and the ePolicy Institute found that 60 percent of organizations they contacted used software to monitor employees' e-mail correspondence with parties outside the firm (American Management Association & ePolicy Institute, 2004). Although regulatory controls on monitoring and surveillance are sometimes stricter in other locales, such as Canada, Western Europe, Japan, and Australia, the use of electronic monitoring and surveillance of workers and workgroups occurs in those places as well...

„Über diesen Titel“ kann sich auf eine andere Ausgabe dieses Titels beziehen.

Weitere beliebte Ausgaben desselben Titels

9781937290696: Visible Employee

Vorgestellte Ausgabe

ISBN 10:  1937290697 ISBN 13:  9781937290696
Softcover