The positive outcomes of information security awareness training in companies - A case study
نویسندگان
چکیده
One of the key factors in successful information security management is the effective compliance of security policies and proper integration of “people”, “process” and “technology”. When it comes to the issue of “people”, this effectiveness can be achieved through several mechanisms, one of which is the security awareness training of employees. However, the outcomes should also be measured to see how successful and effective this training has been for the employees. In this study, an information security awareness project is implemented in a company both by training and by subsequent auditing of the effectiveness and success of this training (which focussed on password usage, password quality and compliance of employees with the password policies of the company). The project was conducted in a Turkish company with 2900 white-collar employees. Each employee took information security training including password usage. Also, there were several supporting awareness campaigns such as educational posters, animations and e-messages on the company Intranet, surveys and simple online quizzes. The project was carried out over a 12 month period and three password security strength audits were made during this period. The results were comparatively and statistically analysed. The results show us the effectiveness of the project and the impact of human awareness on the success of information security management programmes in companies. This study gives us some crucial results, facts and methods that can also be used as a guideline for further similar projects. a 2010 Elsevier Ltd. All rights reserved.
منابع مشابه
An Information Security Training and Awareness Approach (ISTAAP) to Instil an Information Security-Positive Culture
This paper proposes a unique information security training and awareness approach (ISTAAP) that can be used to instil an information security-positive culture which will assist in addressing the risk that human behaviour poses to the protection of information. An information security culture assessment tool is used as the critical diagnostic instrument to assess the information security culture...
متن کاملThe Effect of Delivering Educational Programs through Telegram Messenger on Improving the Awareness of Learners (A Case Study of Prevention of Hospital Infections among Health Workers in Bam)
Introduction: Hospital infections are one of the most important problems in each health care system the use of social media provides a powerful tool in the education process for health educators. The aim of this study was to evaluate the quality of the educational programs delivered through telegram messenger and its influence on improving the awareness of health workers in the prevention of ho...
متن کاملTowards A Needs Assessment Process Model For Security, Education, Training And Awareness Programs: An Action Design Research Study
Employees are considered to be the weakest link in information systems (IS) security. Many companies and organizations started to implement security education, training and awareness (SETA) programs. These provide their employees awareness of information security risks and the necessary skills to protect a companies’ or organizations’ information assets. To ensure that SETA programs are efficie...
متن کاملThe Effect of Delivering Educational Programs through Telegram Messenger on Improving the Awareness of Learners (A Case Study of Prevention of Hospital Infections among Health Workers in Bam)
Introduction: Hospital infections are one of the most important problems in each health care system the use of social media provides a powerful tool in the education process for health educators. The aim of this study was to evaluate the quality of the educational programs delivered through telegram messenger and its influence on improving the awareness of health workers in the prevention of ho...
متن کاملThe effect of developing the dynamics of library software system on information security management (Case study: Libraries of Islamic Azad universities of the country)
Background and Objective: Information security is of vital importance in most organizations. This is especially central in academic libraries due to the specific type of visitors, exchange and transfer of information to the users. Thus, the purpose is to investigate the relationship of the development of library software and information security management in the libraries of Islamic Azad Uni...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- Inf. Sec. Techn. Report
دوره 14 شماره
صفحات -
تاریخ انتشار 2009