When senior leadership reviews an information security baseline, they see architecture diagrams, identity management policies, and encryption tiers. Everything is rationalized into controls.
Yet when you sit inside an operational branch handling sensitive taxpayer records or protected intelligence, the real threat vectors rarely look like brute-force intrusions. They look like informal workarounds invented by well-intentioned staff trying to meet statutory performance deadlines.
The friction of security controls
Security controls that introduce high friction without understanding operational workflows inevitably generate underground procedures. When transferring an encrypted file between secure enclaves takes forty minutes due to multi-hop authentication gates, officers find ways to summarize or re-key information into less restrictive zones.
> Security policy that ignores administrative friction is an unfunded mandate for non-compliance.
Information hygiene as administrative practice
Addressing this gap requires moving beyond compliance audits toward ethnographic workflow analysis. Information security in the public sector cannot merely be an IT governance checklist; it must be taught as an organic craft of administrative justice.
In my doctoral investigations, I study how institutional memory and local peer training mitigate security decay far more effectively than punitive compliance sanctions.