The Misunderstood Link: Information Security Training Strategy Emergent Research Forum (ERF)

被引:0
|
作者
Torres, Henry G. [1 ]
Gupta, Saurabh [2 ]
机构
[1] Arkansas State Univ, State Univ, AR 72467 USA
[2] Kennesaw State Univ, Kennesaw, GA 30144 USA
来源
关键词
Information security; training; information security training; security education training; information security training strategy; training strategy; phishing; security awareness; SETA; design science; DESIGN SCIENCE; FEAR APPEALS; IMPACT;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Insecure user behavior and failure to identify phishing is a leading cause of information security breaches triggering increased company costs in keeping information secure. Training employees toward secure information systems (IS) behavior is a way for organizations to attempt keeping information secure. Herein we outline how using traditional goals for information security training is a contributing factor to continued rise of insecure employee behavior. We posit that the approach to information security training recommended in extant literature is failing because of focus on improving skills in procedural, policy, and compliance activities. We propose a model suggesting alternative goals and draws propositions regarding its effectiveness. The model is of interest to investigate if using a training design that includes goals/inputs matching tools and users, a training process matching inputs to methods, and knowledge transfer outcomes emphasizing affective and meta cognitive learning, has a positive impact on secure behavior when using IS. The paper presents a design science model for a training strategy regarding information systems secure behavior.
引用
收藏
页数:5
相关论文
共 50 条