论文标题
“我的安全隐私”:使用企业安全软件时员工的隐私观点和期望
"My Privacy for their Security": Employees' Privacy Perspectives and Expectations when using Enterprise Security Software
论文作者
论文摘要
通常要求员工在公司和个人设备上使用企业安全软件(“ ESS”)。 ESS产品收集用户的活动数据,包括用户的位置,所使用的应用程序和访问的网站 - 从员工的设备运行到云。据我们所知,该数据收集的隐私影响尚未探索。我们对在线调查(n = 258)和与ESS用户进行半结构化访谈(n = 22),以了解他们的隐私感,他们在使用ESS时面临的挑战以及他们试图克服这些挑战的方式。我们发现,尽管许多参与者报告没有收到有关其ESS收集的数据的信息,但收到一些信息的人经常低估收集的内容。员工报告说缺乏有关各种数据收集方面的沟通,包括:具有访问数据和收集数据范围的实体。我们使用访谈来发现参与者之间的几种误解来源。我们的发现表明,尽管员工了解对安全数据收集的需求,但缺乏通信和模棱两可的数据收集实践导致员工对ESS和雇主的信任侵蚀。我们从参与者那里获得有关如何减轻这些误解的建议,并收集有关我们关于ESS的隐私通知和隐私指标的设计模型的反馈。我们的工作将使研究人员,雇主和ESS开发人员受益,以保护用户在不断增长的ESS市场中的隐私。
Employees are often required to use Enterprise Security Software ("ESS") on corporate and personal devices. ESS products collect users' activity data including users' location, applications used, and websites visited - operating from employees' device to the cloud. To the best of our knowledge, the privacy implications of this data collection have yet to be explored. We conduct an online survey (n=258) and a semi-structured interview (n=22) with ESS users to understand their privacy perceptions, the challenges they face when using ESS, and the ways they try to overcome those challenges. We found that while many participants reported receiving no information about what data their ESS collected, those who received some information often underestimated what was collected. Employees reported lack of communication about various data collection aspects including: the entities with access to the data and the scope of the data collected. We use the interviews to uncover several sources of misconceptions among the participants. Our findings show that while employees understand the need for data collection for security, the lack of communication and ambiguous data collection practices result in the erosion of employees' trust on the ESS and employers. We obtain suggestions from participants on how to mitigate these misconceptions and collect feedback on our design mockups of a privacy notice and privacy indicators for ESS. Our work will benefit researchers, employers, and ESS developers to protect users' privacy in the growing ESS market.