The Utility of Information Security Training and Education on Cybersecurity Incidents: An empirical evidence

被引:0
|
作者
Eunkyung Kweon
Hansol Lee
Sangmi Chai
Kyeongwon Yoo
机构
[1] Ewha Womans University,
[2] Sangmyung University,undefined
来源
关键词
Information security incidents; Information security training; Information security management; Poisson regression analysis;
D O I
暂无
中图分类号
学科分类号
摘要
As recent cyber-attacks have been increasing exponentially, the importance of security training for employees also has become growing ever than before. In addition, it is suggested that security training and education be an effective method for discerning cyber-attacks within academia and industries. Despite the importance and the necessity of the training, prior study did not investigate the quantitative utility of security training in an organizational level. Due to the absence of referential studies, many firms are having troubles in making decisions with respect to arranging optimal security training programs with limited security budgets. The main objective of this study is to find out a relationship between cybersecurity training and the number of incidents of organizations. Thus, this study quantified the effectiveness of security training on security incidents as the first study. This research examined the relationship among three main factors; education time, education participants, and outsourcing with numbers of cybersecurity incidents. 7089 firm level data is analyzed through Poisson regression method. Based on analysis results, we found that the negative relationship between security trainings and the occurrence of cybersecurity incidents. This study sheds light on the role of security training and education by suggesting its positive association with reducing the number of incidents in organizations from the quantitative perspective. The result of this study can be used as a referential guide for information security training decision-making procedure in organizations.
引用
收藏
页码:361 / 373
页数:12
相关论文
共 50 条
  • [21] Leveraging information security and computational trust for cybersecurity
    de Oliveira Albuquerque, Robson
    Garcia Villalba, Luis Javier
    Sandoval Orozco, Ana Lucila
    de Sousa, Rafael Timoteo
    Kim, Tai-Hoon
    JOURNAL OF SUPERCOMPUTING, 2016, 72 (10): : 3729 - 3763
  • [22] Information security management incidents in research–development
    Finat, Carmen (carmen.finat@incdmtm.ro), 1600, Editura ASE Bucuresti
  • [23] Reputation Risks through Information Security Incidents
    Eduardovich, Dorokhov Vitaliy
    Vladimirovich, Yankevskiy Alexey
    PROCEEDINGS OF THE 2016 IEEE NORTH WEST RUSSIA SECTION YOUNG RESEARCHERS IN ELECTRICAL AND ELECTRONIC ENGINEERING CONFERENCE (ELCONRUSNW), 2016, : 194 - 198
  • [24] State Management Mechanisms for the Exchange of Information Regarding Cyberattacks, Cyber Incidents and Information Security Incidents
    Kryshtanovych, Myroslav
    Britchenko, Igor
    Losonczi, Peter
    Baranovska, Tetiana
    Lukashevska, Ulyana
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2022, 22 (04): : 33 - 38
  • [25] A performance analysis model for the training and education of information security talents
    Li L.
    Zhang K.
    Li T.
    International Journal of Emerging Technologies in Learning, 2020, 15 (05) : 140 - 155
  • [26] Media education in training students to provide information and psychological security
    Kislyakov, P. A.
    Shmeleva, E. A.
    MEDIAOBRAZOVANIE-MEDIA EDUCATION, 2018, (01): : 107 - 116
  • [27] A Performance Analysis Model for the Training and Education of Information Security Talents
    Li, Lin
    Zhang, Kai
    Li, Tao
    INTERNATIONAL JOURNAL OF EMERGING TECHNOLOGIES IN LEARNING, 2020, 15 (05): : 140 - 155
  • [28] Identifying the Organizational Factors of Information Security Incidents
    Almubark, Abdullah
    Hatanaka, Nobutoshi
    Uchida, Osamu
    Ikeda, Yukiyo
    2015 SECOND INTERNATIONAL CONFERENCE ON COMPUTING TECHNOLOGY AND INFORMATION MANAGEMENT (ICCTIM), 2015, : 7 - 12
  • [29] Incorporating hacking projects in computer and information security education: an empirical study
    Alashwali, Eman
    INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2014, 6 (03) : 185 - 203
  • [30] Information Technology (IT) Integration and Cybersecurity/Security: The Security Savviness of Board of Directors
    Islam, Md Shariful
    Stafford, Thomas
    AMCIS 2017 PROCEEDINGS, 2017,