Improving Security Awareness and Training through Computer-based Training

نویسندگان

  • Steven M Furnell
  • Alastair G Warren
  • Paul S Dowland
چکیده

Security awareness is a critical issue for all organisations that depend upon information technology. However, significant survey evidence suggests that the issue is often given inadequate attention in modern organisations, leading to problems through security incidents. This paper considers various means that can be used to instil greater awareness, and argues that the most effective method is likely to be via training and awareness programmes. Unfortunately, organisational constraints often preclude the pursuit of such programmes (either in-house or externally) in a traditional manner, and a substitute is needed that can be accessed on-demand, in a self-paced manner. Thus the use of computer-based training is proposed, and the paper discusses the ongoing realisation of an appropriate training tool. The prototype provides an environment that permits the user to explore security problem scenarios, and then select appropriate countermeasures to address the issues identified. It is considered that such an approach would be suitable for promoting day-to-day security awareness for general users, and conducting more specific training for staff with greater security responsibilities.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Measures for improving information security management in organisations: the impact of training and awareness programmes

Security breaches have attracted corporate attention and major organisations are now determined to stop security breaches as they are detrimental to their success. Users’ security awareness and cautious behaviour play an important role in information security both within and outside the organisation. Arguably the most common factor contributing to these breaches is that of human behaviour towar...

متن کامل

Cyber Security Training and Awareness Through Game Play

Although many of the concepts included in staff cyber-security awareness training are universal, such training often must be tailored to address the policies and requirements of a particular organization. In addition, many forms of training fail because they are rote and do not require users to think about and apply security concepts. A flexible, highly interactive video game, CyberCIEGE, is de...

متن کامل

Awareness Training Transfer and Information Security Content Development for Healthcare Industry

Electronic Health Record (EHR) becomes increasingly pervasive and the need to safeguard EHR becomes more vital for healthcare organizations. Human error is known as the biggest threat to information security in Electronic Health Systems that can be minimized through awareness training programs. There are various techniques available for awareness of information security. However, research is sc...

متن کامل

The Effect of Delivering Educational Programs through Telegram Messenger on Improving the Awareness of Learners (A Case Study of Prevention of Hospital Infections among Health Workers in Bam)

Introduction: Hospital infections are one of the most important problems in each health care system the use of social media provides a powerful tool in the education process for health educators. The aim of this study was to evaluate the quality of the educational programs delivered through telegram messenger and its influence on improving the awareness of health workers in the prevention of ho...

متن کامل

A video game for cyber security training and awareness

Although many of the concepts included in cyber security awareness training are universal, such training often must be tailored to address the policies and requirements of a particular organization. In addition, many forms of training fail because they are rote and do not require users to think about and apply security concepts. A flexible, highly interactive video game, CyberCIEGE, is describe...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2008