Skip to main content
QUICK REVIEW

[论文解读] Do They Accept or Resist Cybersecurity Measures? Development and Validation of the 13-Item Security Attitude Inventory (SA-13)

Cori Faklaris, Laura Dabbish|arXiv (Cornell University)|Apr 6, 2022
Information and Cyber Security被引用 5
一句话总结

本文介绍了13项安全态度量表(SA-13),这是一种经过验证的心理测量工具,用于衡量用户对网络安全措施的态度。该量表识别出四个不同的维度——参与度、警觉性、抵触性与关切度——具有较强的内部一致性及对安全行为意图和自报行为的预测效度。

ABSTRACT

We present SA-13, the 13-item Security Attitude inventory. We develop and validate this assessment of cybersecurity attitudes by conducting an exploratory factor analysis, confirmatory factor analysis, and other tests with data from a U.S. Census-weighted Qualtrics panel (N=209). Beyond a core six indicators of Engagement with Security Measures (SA-Engagement, three items) and Attentiveness to Security Measures (SA-Attentiveness, three items), our SA-13 inventory adds indicators of Resistance to Security Measures (SA-Resistance, four items) and Concernedness with Improving Compliance (SA-Concernedness, three items). SA-13 and the subscales exhibit desirable psychometric qualities; and higher scores on SA-13 and on the SA-Engagement and SA-Attentiveness subscales are associated with higher scores for security behavior intention and for self-reported recent security behaviors. SA-13 and the subscales are useful for researchers and security awareness teams who need a lightweight survey measure of user security attitudes. The composite score of the 13 indicators provides a compact measurement of cybersecurity decisional balance.

研究动机与目标

  • 开发一种可靠且有效的测量个体对网络安全措施态度的工具。
  • 识别用户态度的各个维度,包括参与度、警觉性、对合规性的抵触与关切。
  • 使用来自代表性美国样本的实证数据,验证SA-13的心理测量特性。
  • 使研究人员和从业者能够通过一种轻量化、可扩展的调查工具,评估网络安全行为中的决策平衡。
  • 通过测量用户对安全实践的倾向性,支持设计针对性的安全意识干预措施。

提出的方法

  • 对209名美国参与者的调查数据进行探索性因子分析(EFA),以识别用户态度的潜在维度。
  • 通过验证性因子分析(CFA)验证SA-13的四因素结构:SA-参与度、SA-警觉性、SA-抵触性与SA-关切度。
  • 使用Cronbach’s alpha评估整体量表及各子量表的内部一致性。
  • 通过与安全行为意图及自报安全行为的相关性,检验聚合效度与区分效度。
  • 使用基于美国人口普查加权的Qualtrics调查样本面板,确保样本的人口统计代表性。
  • 在附录中提供详细的实施说明,便于在研究和组织环境中实际部署。

实验结果

研究问题

  • RQ1个体对网络安全措施的态度背后有哪些潜在维度?
  • RQ213项SA-13量表在测量这些态度方面的信度与效度如何?
  • RQ3SA-13得分在多大程度上能预测与网络安全相关的意图与实际行为?
  • RQ4各子量表(参与度、警觉性、抵触性、关切度)与安全行为的关联性有何差异?
  • RQ5SA-13能否作为一种简洁、心理测量学上可靠的工具,用于衡量网络安全采纳中的决策平衡?

主要发现

  • SA-13表现出较强的内部一致性,整体量表的Cronbach’s alpha为0.89,所有子量表的Cronbach’s alpha均高于0.70。
  • 验证性因子分析证实了四因素模型具有良好的拟合指数,支持四个独立态度维度的有效性。
  • SA-13综合得分与更高的安全行为意图显著相关(r = 0.45,p < 0.001)。
  • 在SA-参与度和SA-警觉性上得分较高的参与者,报告了更频繁的自报安全行为(β = 0.31 和 β = 0.28,分别,p < 0.01)。
  • SA-抵触性与安全行为意图呈负相关(r = -0.33,p < 0.001),表明抵触情绪会阻碍合规行为。
  • SA-13综合得分有效捕捉了决策平衡,反映了对安全措施接受与抵触之间的动态互动。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。