PB-11 · Moderate evidence
Raises security friction openly
Tells the security team when a rule blocks their work, instead of quietly building a workaround.
When policy clashes with getting work done, conscientious people invent their own 'shadow security'. Surfacing the clash lets the organization fix the policy.
How to observe it: Volume of policy-friction feedback; share of workarounds discovered by report rather than audit.
Supporting evidence- Learning from “Shadow Security:” Why Understanding Non-Compliant Behaviors Provides the Basis for Effective Security Kirlappos et al., 2014
- Users are not the enemy Adams & Sasse, 1999
- The compliance budget: managing security behaviour in organisations Beautement et al., 2008