How to measure IT security awareness of employees: a comparison to e-mail surveillance at the workplace
Measuring and improving IT security awareness of employees is of crucial importance considering the damages that occur through attacks on the IT security of companies each year. The paper presents a German research project, which intends to improve the IT security awareness of employees while at the same time considering the rights of individuals concerned. The authors address one specific labour law issue dealing with the question of how to ensure that there will not be an adverse impact on the employees’ rights while clandestinely testing their IT security awareness. A parallel will be drawn to the case of e-mail surveillance at the workplace under EU and German law and its findings transferred to the project scenario. On this basis, suggestions for lawful test methods measuring the employees’ IT security awareness will be made.
Keywords: IT-security awareness; Critical infrastructures; Penetration testing; Surveillance at the workplace; Surveillance of business e-mail accounts; Privacy by design; Fundamental rights of employees
EJLT is an open access journal, aiming to disseminate academic work and perspectives as widely as possible to the benefit of the author and the author’s readers. It is the assumption of the EJLT that authors who publish in the journal wish their work to be available as freely and as widely as possible through the open access publishing channel.
Authors who publish with EJLT will retain copyright and moral rights in the underlying work but will grant all users the rights to copy, store and print for non-commercial use copies of their work. Commercial mirroring may also be carried out with the consent of the journal. The work must remain as published – without redaction or editing – and must clearly state the identity of the author and the originating EJLT url of the article. Any commercial use of the author’s work - apart from mirroring - requires the permission of the author and any aspects of the article which are the property of EJLT (e.g. typographical format) requires permission from EJLT.
Authors can sometimes become no longer contactable (through, for example, death or retirement). If this occurs, any rights in the work will pass to the European Journal of Law and Technology which will continue to make the work available in as wide a manner as possible to achieve the aims of open access and ensuring that an author's work continues to be available. An author - or their estate - can recover these rights from EJLT by providing contact information.
The European Journal of Law and Technology holds rights in format, publication and dissemination.
EJLT, as a non-commercial organisation - which receives donations to allow it to continue publishing – must retain information on reader access to journal articles. This means that we will not give permission to mirror the journal unless we can be provided with full details as to reader access to each and every journal article. We prefer and encourage deep linking rather than mirroring. Encouragement is thus given for all users – commercial and non-commercial – to provide indexes and links to articles in the EJLT where the index or link points to the location of the article on the EJLT server, rather than to stored copies on other servers.
Please contact the European Journal of Law and Technology if you are in any doubt as to what this statement of use covers.