Measures for improving information security management in organisations: the impact of training and awareness programmes
نویسندگان
چکیده
Security breaches have attracted corporate attention and major organisations are now determined to stop security breaches as they are detrimental to their success. Users’ security awareness and cautious behaviour play an important role in information security both within and outside the organisation. Arguably the most common factor contributing to these breaches is that of human behaviour towards security, which suggests that changes in human behaviour can have an impact on improving security. One of the measures suggested to modify employee behaviour is through training and awareness-raising. However, before effective training and awareness programmes can be developed to achieve this aim, it is essential to understand what factors influence user behaviour and attitudes to information security. For this study, interviews with employees within the public and private sector were conducted to explore factors that influence security behaviour when using information. Our findings offer some preliminary recognition of implications for the designs of more effective training and awareness programmes that assure and sustain, in the long term, the appropriate behaviour towards security. Keywords—Information security, awareness, security behaviour, training and awareness programme, qualitative research.
منابع مشابه
Improving Security Awareness and Training through Computer-based Training
Security awareness is a critical issue for all organisations that depend upon information technology. However, significant survey evidence suggests that the issue is often given inadequate attention in modern organisations, leading to problems through security incidents. This paper considers various means that can be used to instil greater awareness, and argues that the most effective method is...
متن کاملLeadership and Leadership Development in Healthcare Settings – A Simplistic Solution to Complex Problems?
There is a trend in health systems around the world to place great emphasis on and faith in improving ‘leadership’. Leadership has been defined in many ways and the elitist implications of traditional notions of leadership sit uncomfortably with modern healthcare organisations. The concept of distributed leadership incorporates inclusivity, collectiveness and collaboration, with the result that...
متن کاملImproving Information Security Training: An Intercultural Perspective
To ensure successful compliance with information security (InfoSec) policy and standards, organisations must harmonise their InfoSec training programmes with the national culture of the local workforce. A successful InfoSec policy must demonstrate the value of security, not just the requirement for security. We conducted a quantitative study of 177 professionals across 35 national cultures to i...
متن کاملOutcomes and Impact of Training and Development in Health Management and Leadership in Relation to Competence in Role: A Mixed-Methods Systematic Review Protocol
Background The need for competence training and development in health management and leadership workforces has been emphasised. However, evidence of the outcomes and impact of such training and development has not been systematically assessed. The aim of this review is to synthesise the available evidence of the outcomes and impact of training and development in relation to the competence of he...
متن کاملThe Embedded Health Management Academic: A Boundary Spanning Role for Enabling Knowledge Translation; Comment on “CIHR Health System Impact Fellows: Reflections on ‘Driving Change’ Within the Health System”
Healthcare organisations are looking at strategies and activities to improve patient outcomes, beyond clinical interventions. Increasingly, health organisations are investing significant resources in leadership, management and team work training to optimise professional collaboration, shared decision-making and, by extension, high quality services. Embedded clinical aca...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2012