Applied Holistic Approach For Security Awareness And Training - Computer Games As Means To Increase Users' Information And Communication Security Awareness
نویسنده
چکیده
In order to decrease Information and Communication Technology (ICT) security threats caused by human errors an increased concentration on education and learning is necessary. Because of the large amount of new users, with different kind of learning capabilities, the traditional teaching methods are not sufficient. Alternative forms of education are needed. This article discusses why ICT security functionalities are important to understand and how nonlinear interactive computer games can support the holistic understanding of ICT from a security perspective. Through visualizing common security functionalities a practical attempt to make learners understand the basic concepts of Public Key Infrastructure (PKI) is described, why it is needed and how these concepts can be applied in the daily use of ICT. The findings from several conducted experiments investigating the effect learning through a single-user computer game has on the acquired knowledge will also be presented and discussed. The findings show that a computer game can be an efficient instrument when learning to understand ICT security.
منابع مشابه
Personalising information security education
Personalising Information Security Education Shuhaili Talib Whilst technological solutions go a long way in providing protection for users online, it has been long understood that the individual also plays a pivotal role. Even with the best of protection, an illinformed person can effectively remove any protection the control might provide. Information security awareness is therefore imperative...
متن کاملThe Impact of Information Security Awareness Training on Information Security Behaviour: The Case for Further Research
Information Security awareness initiatives are seen as critical to any information security programme. But, how do we determine the effectiveness of these awareness initiatives? We could get our employees to write a test afterwards to determine how well they understand the policies, but this does not show how it affects the employee’s on the job behaviour. Does awareness training have a direct ...
متن کاملImproving Security Awareness and Training through Computer-based Training
Security awareness is a critical issue for all organisations that depend upon information technology. However, significant survey evidence suggests that the issue is often given inadequate attention in modern organisations, leading to problems through security incidents. This paper considers various means that can be used to instil greater awareness, and argues that the most effective method is...
متن کاملA video game for cyber security training and awareness
Although many of the concepts included in cyber security awareness training are universal, such training often must be tailored to address the policies and requirements of a particular organization. In addition, many forms of training fail because they are rote and do not require users to think about and apply security concepts. A flexible, highly interactive video game, CyberCIEGE, is describe...
متن کاملA design theory for information security awareness
When implementing their information security solutions organizations have typically focused on technical and procedural security measures. However, from the information systems (IS) point of view, this is not enough: effective IS security requires that users are aware of and use the available security measures as described in their organizations' information security policies and instructions. ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2004