The Utility of Information Security Training and Education on Cybersecurity Incidents: An empirical evidence

被引:0
|
作者
Eunkyung Kweon
Hansol Lee
Sangmi Chai
Kyeongwon Yoo
机构
[1] Ewha Womans University,
[2] Sangmyung University,undefined
来源
关键词
Information security incidents; Information security training; Information security management; Poisson regression analysis;
D O I
暂无
中图分类号
学科分类号
摘要
As recent cyber-attacks have been increasing exponentially, the importance of security training for employees also has become growing ever than before. In addition, it is suggested that security training and education be an effective method for discerning cyber-attacks within academia and industries. Despite the importance and the necessity of the training, prior study did not investigate the quantitative utility of security training in an organizational level. Due to the absence of referential studies, many firms are having troubles in making decisions with respect to arranging optimal security training programs with limited security budgets. The main objective of this study is to find out a relationship between cybersecurity training and the number of incidents of organizations. Thus, this study quantified the effectiveness of security training on security incidents as the first study. This research examined the relationship among three main factors; education time, education participants, and outsourcing with numbers of cybersecurity incidents. 7089 firm level data is analyzed through Poisson regression method. Based on analysis results, we found that the negative relationship between security trainings and the occurrence of cybersecurity incidents. This study sheds light on the role of security training and education by suggesting its positive association with reducing the number of incidents in organizations from the quantitative perspective. The result of this study can be used as a referential guide for information security training decision-making procedure in organizations.
引用
收藏
页码:361 / 373
页数:12
相关论文
共 50 条
  • [1] The Utility of Information Security Training and Education on Cybersecurity Incidents: An empirical evidence
    Kweon, Eunkyung
    Lee, Hansol
    Chai, Sangmi
    Yoo, Kyeongwon
    INFORMATION SYSTEMS FRONTIERS, 2021, 23 (02) : 361 - 373
  • [2] Gathering digital evidence in response to information security incidents
    Wang, SJ
    Yang, CH
    INTELLIGENCE AND SECURITY INFORMATICS, PROCEEDINGS, 2005, 3495 : 644 - 645
  • [3] Procedural response and digital evidence exposure in information security incidents
    Wang, Shiuh-Jeng
    JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY, 2006, 9 (03): : 417 - 427
  • [4] Corporate management boards’ information security orientation: an analysis of cybersecurity incidents in DAX 30 companies
    L. Georg-Schaffner
    E. Prinz
    Journal of Management and Governance, 2022, 26 : 1375 - 1408
  • [5] Corporate management boards' information security orientation: an analysis of cybersecurity incidents in DAX 30 companies
    Georg-Schaffner, L.
    Prinz, E.
    JOURNAL OF MANAGEMENT & GOVERNANCE, 2022, 26 (04) : 1375 - 1408
  • [6] An empirical study on the use of the Generic Security Template for structuring the lessons from information security incidents
    He, Ying
    Johnson, Chris
    Renaud, Karen
    Lu, Yu
    Jebriel, Salem
    2014 6TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND INFORMATION TECHNOLOGY (CSIT), 2014, : 178 - 188
  • [7] A Conceptual Analysis of Information Security Education, Information Security Training and Information Security Awareness Definitions
    Amankwa, Eric
    Loock, Marianne
    Kritzinger, Elmarie
    2014 9TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2014, : 248 - 252
  • [8] Research on Information Literacy Training and Information Security Education
    Zang AiJun
    Wang ChunYu
    PROCEEDINGS OF 2012 7TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE & EDUCATION, VOLS I-VI, 2012, : 1754 - 1757
  • [9] Korea’s cybersecurity regulations and enforcement related to security incidents
    Kwang Bae Park
    Sunghee Chae
    Hyein Lee
    International Cybersecurity Law Review, 2021, 2 (1): : 47 - 55
  • [10] Empirical Analysis of the Effects of Cyber Security Incidents
    Davis, Ginger
    Garcia, Alfredo
    Zhang, Weide
    RISK ANALYSIS, 2009, 29 (09) : 1304 - 1316