{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T17:39:37Z","timestamp":1785605977890,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":44,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,8,31]]},"DOI":"10.1145\/3743049.3743052","type":"proceedings-article","created":{"date-parts":[[2025,8,28]],"date-time":"2025-08-28T14:03:01Z","timestamp":1756389781000},"page":"1-16","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["LAURA: A Framework for Assessing the Usability of IT Security Policies Based on Learnability, Actionability, Understandability, Relevance, and Abstraction"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-6902-7061","authenticated-orcid":false,"given":"Mario","family":"Hoffmann","sequence":"first","affiliation":[{"name":"IT Department, Leipzig University, Leipzig, Saxony, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0302-6479","authenticated-orcid":false,"given":"Francesca","family":"M\u00fcller","sequence":"additional","affiliation":[{"name":"Department of Civil Protection and Disaster Relief, University Wuppertal, Wuppertal, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4987-7308","authenticated-orcid":false,"given":"Arthur","family":"Fleig","sequence":"additional","affiliation":[{"name":"Center for Scalable Data Analytics and Artificial Intelligence (ScaDS.AI) Dresden\/Leipzig, Leipzig University, Leipzig, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,8,30]]},"reference":[{"key":"e_1_3_3_1_2_2","doi-asserted-by":"publisher","unstructured":"Anne Adams and Martina\u00a0Angela Sasse. 1999. Users are not the enemy. Commun. ACM 42 12 (Dec. 1999) 40\u201346. 10.1145\/322796.322806","DOI":"10.1145\/322796.322806"},{"key":"e_1_3_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/3603555.3603573"},{"key":"e_1_3_3_1_4_2","volume-title":"Wie verst\u00e4ndlich sind unsere Zeitungen?","author":"Amstad Toni","year":"1978","unstructured":"Toni Amstad. 1978. Wie verst\u00e4ndlich sind unsere Zeitungen?Studenten-Schreib-Service, Z\u00fcrich."},{"key":"e_1_3_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/1595676.1595684"},{"key":"e_1_3_3_1_6_2","doi-asserted-by":"publisher","unstructured":"Melissa\u00a0C. Brouwers Michelle\u00a0E. Kho George\u00a0P. Browman Jako\u00a0S. Burgers Francoise Cluzeau Gene Feder B\u00e9atrice Fervers Ian\u00a0D. Graham Jeremy Grimshaw Steven\u00a0E. Hanna Peter Littlejohns Julie Makarski and Louise Zitzelsberger. 2010. AGREE II: Advancing guideline development reporting and evaluation in health care. Journal of Clinical Epidemiology 63 12 (2010) 1308\u20131311. 10.1016\/j.jclinepi.2010.07.001","DOI":"10.1016\/j.jclinepi.2010.07.001"},{"key":"e_1_3_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1515\/9783110443905-087"},{"key":"e_1_3_3_1_8_2","unstructured":"European Union. 2016. REGULATION (EU) 2016\/679 of the European Parliament AND OF THE Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95\/46\/EC (General Data Protection Regulation). Official Journal of the European Union L119\/1 (2016) 156\u00a0pages."},{"key":"e_1_3_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/3340764.3340789"},{"key":"e_1_3_3_1_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/986655.986664"},{"key":"e_1_3_3_1_11_2","unstructured":"Nancy Flynn. 2011. Writing Effective Policies. The ePolicy Institute and Prevalent Networks 1 1 (2011) 12."},{"key":"e_1_3_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/3706599.3719816"},{"key":"e_1_3_3_1_13_2","unstructured":"Bundesamt f\u00fcr Sicherheit in\u00a0der Informationstechnik. 2025. https:\/\/www.bsi.bund.de\/dok\/6617938. Accessed: 07.03.2025."},{"key":"e_1_3_3_1_14_2","doi-asserted-by":"publisher","unstructured":"Syama Gollapalli Richard Bresler Noel\u00a0P Lynch and Sean\u00a0T Martin. 2022. Treatment for Constipation\u2014An Online Search. Readability and Quality of Online Patient Resources. Journal of Patient Experience 9 (2022) 16. 10.1177\/23743735221102675 PMID: 35647271.","DOI":"10.1177\/23743735221102675"},{"key":"e_1_3_3_1_15_2","doi-asserted-by":"publisher","unstructured":"Gordon\u00a0H Guyatt Andrew\u00a0D Oxman Gunn\u00a0E Vist Regina Kunz Yngve Falck-Ytter Pablo Alonso-Coello and Holger\u00a0J Sch\u00fcnemann. 2008. GRADE: an emerging consensus on rating quality of evidence and strength of recommendations. BMJ 336 7650 (2008) 924\u2013926. 10.1136\/bmj.39489.470347.AD","DOI":"10.1136\/bmj.39489.470347.AD"},{"key":"e_1_3_3_1_16_2","doi-asserted-by":"publisher","unstructured":"Tejaswini Herath and H.R. Rao. 2009. Encouraging information security behaviors in organizations: Role of penalties pressures and perceived effectiveness. Decision Support Systems 47 2 (2009) 154\u2013165. 10.1016\/j.dss.2009.02.005","DOI":"10.1016\/j.dss.2009.02.005"},{"key":"e_1_3_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/1719030.1719050"},{"key":"e_1_3_3_1_18_2","doi-asserted-by":"publisher","unstructured":"Sadaf Hina and P.\u00a0Dhanapal\u00a0Durai Dominic. 2020. Information security policies\u2019 compliance: a perspective for higher education institutions. Journal of Computer Information Systems 60 3 (2020) 201\u2013211. 10.1080\/08874417.2018.1432996","DOI":"10.1080\/08874417.2018.1432996"},{"key":"e_1_3_3_1_19_2","first-page":"70","volume-title":"AISyS 2024 The First International Conference on AI-based Systems and Services","volume":"1","author":"Hoffmann Mario","year":"2024","unstructured":"Mario Hoffmann and Erik Buchmann. 2024. ChatSEC: Spicing up Vulnerability Scans with AI for Heterogeneous University IT. In AISyS 2024 The First International Conference on AI-based Systems and Services , Erik Buchmann and Dennis Hoppe (Eds.), Vol.\u00a01. IARIA, IARIA Press, Venice, Italy, 70."},{"key":"e_1_3_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1145\/3334480.3375030"},{"key":"e_1_3_3_1_21_2","unstructured":"Victor J\u00fcttner Martin Grimmer and Erik Buchmann. 2023. ChatIDS: Explainable Cybersecurity Using Generative AI. arxiv:https:\/\/arXiv.org\/abs\/2306.14504\u00a0[cs.CR] https:\/\/arxiv.org\/abs\/2306.14504"},{"key":"e_1_3_3_1_22_2","doi-asserted-by":"publisher","unstructured":"Fredrik Karlsson Martin Karlsson and Joachim \u00c5str\u00f6m. 2017. Measuring employees\u2019 compliance \u2013 the importance of value pluralism. Information & Computer Security 25 3 (Jan. 2017) 279\u2013299. 10.1108\/ICS-11-2016-0084 Publisher: Emerald Publishing Limited.","DOI":"10.1108\/ICS-11-2016-0084"},{"key":"e_1_3_3_1_23_2","doi-asserted-by":"publisher","unstructured":"Marc-Andr\u00e9 Kaufhold Tilo Mentler Simon Nestler and Christian Reuter. 2024. 11. Workshop Mensch-Maschine-Interaktion in sicherheitskritischen Systemen. Mensch und Computer 2024 - Workshopband. 10.18420\/muc2024-mci-ws13-101","DOI":"10.18420\/muc2024-mci-ws13-101"},{"key":"e_1_3_3_1_24_2","unstructured":"Stephanie Kelly and Jessica Resnick-ault. 2021. https:\/\/www.reuters.com\/business\/colonial-pipeline-ceo-tells-senate-cyber-defenses-were-compromised-ahead-hack-2021-06-08\/. Accessed: 07.03.2025."},{"key":"e_1_3_3_1_25_2","doi-asserted-by":"publisher","unstructured":"Mehdi et\u00a0al. Kouhja. 2018. IT Governance in Higher Education Institutions: A Systematic Literature Review. International Journal of Human Capital and Information Technology Professionals (IJHCITP) 9 2 (2018) 52\u201367. 10.4018\/IJHCITP.2018040104","DOI":"10.4018\/IJHCITP.2018040104"},{"key":"e_1_3_3_1_26_2","doi-asserted-by":"publisher","unstructured":"J.\u00a0Richard Landis and Gary\u00a0G. Koch. 1977. The Measurement of Observer Agreement for Categorical Data. Biometrics 33 1 (March 1977) 159. 10.2307\/2529310","DOI":"10.2307\/2529310"},{"key":"e_1_3_3_1_27_2","doi-asserted-by":"publisher","unstructured":"Rebecca Lawton. 1998. Not working to rule: Understanding procedural violations at work. Safety Science 28 2 (1998) 77\u201395. 10.1016\/S0925-7535(97)00073-8","DOI":"10.1016\/S0925-7535(97)00073-8"},{"key":"e_1_3_3_1_28_2","doi-asserted-by":"publisher","unstructured":"Yuchong Li and Qinghui Liu. 2021. A comprehensive review study of cyber-attacks and cyber security; Emerging trends and recent developments. Energy Reports 7 (2021) 8176\u20138186. 10.1016\/j.egyr.2021.08.126","DOI":"10.1016\/j.egyr.2021.08.126"},{"key":"e_1_3_3_1_29_2","doi-asserted-by":"publisher","unstructured":"Katharina L\u00f6hr Michael Weinhardt and Stefan Sieber. 2020. The \u201cWorld Caf\u00e9\u201d as a Participatory Method for Collecting Qualitative Data. International Journal of Qualitative Methods 19 (Jan. 2020) 160940692091697. 10.1177\/1609406920916976","DOI":"10.1177\/1609406920916976"},{"key":"e_1_3_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-658-21308-442"},{"key":"e_1_3_3_1_31_2","doi-asserted-by":"crossref","unstructured":"Abraham Mhaidli Selin Fidan An Doan Gina Herakovic Mukund Srinath Lee Matheson Shomir Wilson and Florian Schaub. 2023. Researchers\u2019 experiences in analyzing privacy policies: Challenges and opportunities. Proceedings on Privacy Enhancing Technologies 2023 4 (2023) 287\u2013305.","DOI":"10.56553\/popets-2023-0111"},{"key":"e_1_3_3_1_32_2","unstructured":"BBC Network. 2021. Meat giant JBS pays $11m in ransom to resolve cyber-attack. https:\/\/www.bbc.com\/news\/business-57423008. Accessed: 07.03.2025."},{"key":"e_1_3_3_1_33_2","doi-asserted-by":"publisher","unstructured":"Lucila Ohno-Machado John\u00a0H. Gennari Shawn\u00a0N. Murphy Nilesh\u00a0L. Jain Samson\u00a0W. Tu Diane\u00a0E. Oliver Edward Pattison-Gordon Robert\u00a0A. Greenes Edward\u00a0H. Shortliffe and G.\u00a0Octo Barnett. 1998. The GuideLine Interchange Format: A Model for Representing Guidelines. Journal of the American Medical Informatics Association 5 4 (07 1998) 357\u2013372. 10.1136\/jamia.1998.0050357","DOI":"10.1136\/jamia.1998.0050357"},{"key":"e_1_3_3_1_34_2","doi-asserted-by":"crossref","unstructured":"Florian Schaub Rebecca Balebako and Lorrie\u00a0Faith Cranor. 2017. Designing effective privacy notices and controls. IEEE Internet Computing 21 3 (2017) 70\u201377.","DOI":"10.1109\/MIC.2017.75"},{"key":"e_1_3_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-658-42483-17"},{"key":"e_1_3_3_1_36_2","doi-asserted-by":"publisher","unstructured":"Mikko Siponen M. Adam Mahmood and Seppo Pahnila. 2014. Employees\u2019 adherence to information security policies: An exploratory field study. Information & Management 51 2 (2014) 217\u2013224. 10.1016\/j.im.2013.08.006","DOI":"10.1016\/j.im.2013.08.006"},{"key":"e_1_3_3_1_37_2","doi-asserted-by":"publisher","unstructured":"Mikko Siponen M.\u00a0Adam Mahmood and Seppo Pahnila. 2009. Technical opinionAre employees putting your company at risk by not following information security policies?Commun. ACM 52 12 (Dec. 2009) 145\u2013147. 10.1145\/1610252.1610289","DOI":"10.1145\/1610252.1610289"},{"key":"e_1_3_3_1_38_2","doi-asserted-by":"publisher","unstructured":"Jai-Yeol Son. 2011. Out of fear or desire? Toward a better understanding of employees\u2019 motivation to follow IS security policies. Information & Management 48 7 (2011) 296\u2013302. 10.1016\/j.im.2011.07.002","DOI":"10.1016\/j.im.2011.07.002"},{"key":"e_1_3_3_1_39_2","doi-asserted-by":"crossref","unstructured":"Nili Steinfeld. 2016. \u201cI agree to the terms and conditions\u201d:(How) do users read privacy policies online? An eye-tracking experiment. Computers in human behavior 55 (2016) 992\u20131000.","DOI":"10.1016\/j.chb.2015.09.038"},{"key":"e_1_3_3_1_40_2","doi-asserted-by":"publisher","unstructured":"Noor\u00a0Suhani Sulaiman Muhammad\u00a0Ashraf Fauzi Walton Wider Jegatheesan Rajadurai Suhaidah Hussain and Siti\u00a0Aminah Harun. 2022. Cyber\u2013Information Security Compliance and Violation Behaviour in Organisations: A Systematic Review. Social Sciences 11 9 (2022) 17\u00a0pages. 10.3390\/socsci11090386","DOI":"10.3390\/socsci11090386"},{"key":"e_1_3_3_1_41_2","doi-asserted-by":"publisher","unstructured":"Anthony Vance Mikko Siponen and Seppo Pahnila. 2012. Motivating IS security compliance: Insights from Habit and Protection Motivation Theory. Information & Management 49 3 (2012) 190\u2013198. 10.1016\/j.im.2012.04.002","DOI":"10.1016\/j.im.2012.04.002"},{"key":"e_1_3_3_1_42_2","doi-asserted-by":"crossref","unstructured":"Judith Versloot Agnes Grudniewicz Ananda Chatterjee Leigh Hayden Monika Kastner and Onil Bhattacharyya. 2015. Format guidelines to make them vivid intuitive and visual: use simple formatting rules to optimize usability and accessibility of clinical practice guidelines. JBI Evidence Implementation 13 2 (2015) 52\u201357.","DOI":"10.1097\/XEB.0000000000000036"},{"key":"e_1_3_3_1_43_2","series-title":"(SSYM\u201999)","first-page":"14","volume-title":"Proceedings of the 8th Conference on USENIX Security Symposium - Volume 8","author":"Whitten Alma","year":"1999","unstructured":"Alma Whitten and J.\u00a0D. Tygar. 1999. Why Johnny can\u2019t encrypt: a usability evaluation of PGP 5.0. In Proceedings of the 8th Conference on USENIX Security Symposium - Volume 8 (Washington, D.C.) (SSYM\u201999). USENIX Association, USA, 14."},{"key":"e_1_3_3_1_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/3544549.3573827"},{"key":"e_1_3_3_1_45_2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-36159-6_24"}],"event":{"name":"MuC '25: Mensch und Computer 2025","location":"Chemnitz Germany","acronym":"MuC '25"},"container-title":["Proceedings of the Mensch und Computer 2025"],"original-title":[],"deposited":{"date-parts":[[2025,8,28]],"date-time":"2025-08-28T14:56:11Z","timestamp":1756392971000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3743049.3743052"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,30]]},"references-count":44,"alternative-id":["10.1145\/3743049.3743052","10.1145\/3743049"],"URL":"https:\/\/doi.org\/10.1145\/3743049.3743052","relation":{},"subject":[],"published":{"date-parts":[[2025,8,30]]},"assertion":[{"value":"2025-08-30","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}