As member of the USIFES project (User-centric, Secure Information Flow in Enterprise Systems) funded by the DFG priority program RS3, Frank Hadasch will present on his past and current work. His talk will have three major parts: (a) Results of his empirical interview study on employees' security behavior, (b) Design of the planned experimental study to investigate how technology-enforcement of security policies changes users' security behavior, and (c) the demonstration of a prototype for a collaborative security policy modeling environment currently being developed and evaluated in the USIFES project.