The positive outcomes of information security awareness training in companies - A case study

نویسندگان

  • Mete Eminagaoglu
  • Erdem Uçar
  • Saban Eren
چکیده

One of the key factors in successful information security management is the effective compliance of security policies and proper integration of “people”, “process” and “technology”. When it comes to the issue of “people”, this effectiveness can be achieved through several mechanisms, one of which is the security awareness training of employees. However, the outcomes should also be measured to see how successful and effective this training has been for the employees. In this study, an information security awareness project is implemented in a company both by training and by subsequent auditing of the effectiveness and success of this training (which focussed on password usage, password quality and compliance of employees with the password policies of the company). The project was conducted in a Turkish company with 2900 white-collar employees. Each employee took information security training including password usage. Also, there were several supporting awareness campaigns such as educational posters, animations and e-messages on the company Intranet, surveys and simple online quizzes. The project was carried out over a 12 month period and three password security strength audits were made during this period. The results were comparatively and statistically analysed. The results show us the effectiveness of the project and the impact of human awareness on the success of information security management programmes in companies. This study gives us some crucial results, facts and methods that can also be used as a guideline for further similar projects. a 2010 Elsevier Ltd. All rights reserved.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

An Information Security Training and Awareness Approach (ISTAAP) to Instil an Information Security-Positive Culture

This paper proposes a unique information security training and awareness approach (ISTAAP) that can be used to instil an information security-positive culture which will assist in addressing the risk that human behaviour poses to the protection of information. An information security culture assessment tool is used as the critical diagnostic instrument to assess the information security culture...

متن کامل

The Effect of Delivering Educational Programs through Telegram Messenger on Improving the Awareness of Learners (A Case Study of Prevention of Hospital Infections among Health Workers in Bam)

Introduction: Hospital infections are one of the most important problems in each health care system the use of social media provides a powerful tool in the education process for health educators. The aim of this study was to evaluate the quality of the educational programs delivered through telegram messenger and its influence on improving the awareness of health workers in the prevention of ho...

متن کامل

Towards A Needs Assessment Process Model For Security, Education, Training And Awareness Programs: An Action Design Research Study

Employees are considered to be the weakest link in information systems (IS) security. Many companies and organizations started to implement security education, training and awareness (SETA) programs. These provide their employees awareness of information security risks and the necessary skills to protect a companies’ or organizations’ information assets. To ensure that SETA programs are efficie...

متن کامل

The Effect of Delivering Educational Programs through Telegram Messenger on Improving the Awareness of Learners (A Case Study of Prevention of Hospital Infections among Health Workers in Bam)

Introduction: Hospital infections are one of the most important problems in each health care system the use of social media provides a powerful tool in the education process for health educators. The aim of this study was to evaluate the quality of the educational programs delivered through telegram messenger and its influence on improving the awareness of health workers in the prevention of ho...

متن کامل

The effect of developing the dynamics of library software system on information security management (Case study: Libraries of Islamic Azad universities of the country)

Background and Objective: Information security is of vital importance in most organizations. This is especially central in academic libraries due to the specific type of visitors, exchange and transfer of information to the users. Thus, the purpose   is to investigate the relationship of the development of library software and information security management in the libraries of Islamic Azad Uni...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • Inf. Sec. Techn. Report

دوره 14  شماره 

صفحات  -

تاریخ انتشار 2009