Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163

Friday, January 22, 2010

Looking for Case Studies and Documents about the Impact of Job Design on Enterprise Security Risks

I am looking for case studies, documents and statistics analysing the impact of job design choices on enterprise (security) risks.

Job design, in a nutshell, involves defining employee roles and related tasks associated for employees in an organisation.

Intuitively, job design decisions have an impact on the productivity of employees, number of accidental & deliberate incidents, exposure to security risks (e.g. by dealing/not dealing with separation of duties and/or empowering too much certain people/roles).

There are interesting studies tacking this issue from an economics perspective, such as the paper on “Limited Intertemporal Commitment and Job Design” (even if it is a little bit too abstract).

So far I have found very little in terms of studies and documents that scientifically analyse how changes in job design affect security risks in an organisation. Any link and reference would really be welcome.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

No comments: