首页> 外文学位 >Motivating Information Security Awareness (ISA): An action research study.
【24h】

Motivating Information Security Awareness (ISA): An action research study.

机译:激励信息安全意识(ISA):一项行动研究。

获取原文
获取原文并翻译 | 示例

摘要

The goal of the study was to identify and analyze specific environmental and social conditions that motivate middle management to advocate for Information Security Awareness (ISA), as well as to see if exposure to new information security knowledge would change their behavior. Using a mixed-method action research approach, a group of managers shared their awareness knowledge, advocacy behaviors, and challenges influencing their engagement in information security awareness advocacy. Post workshop feedback confirmed the effectiveness of the Action Research workshops in increasing ISA advocacy behaviors.;The action research workshops provided an opportunity for the participants to increase their security knowledge and recommend improvements in ISA advocacy practices. Thirty-eight (38) managers, divided among four workshops, participated in the study. Within the research activities, I presented the group with an awareness knowledge self-assessment survey, which captured the managers' view of their own information security knowledge, a sample information security awareness presentation brought context to the workshop, and a group discussion similar to a focus group provided the environment for discussions. During these activities, the managers expressed recommended changes they could drive to improve ISA advocacy. The workshop activities concluded with a closing discussion seeking commitment from the managers to act on the recommendations to improve ISA advocacy. These engagements of learning, and sharing their awareness, supported the main goal of leveraging action research. The findings support the Action Research workshops were an effective tool to increase the participants learning, to improve the practice of ISA advocacy, and to socialize the topic of information security.;The key lessons learned from the research contribute to the overall body of knowledge in the information security awareness discipline as follows. Key finding 1: the feedback on self-reflective levels of knowledge in information security awareness indicated managers are not sufficiently exposed to ISA content. Key finding 2: the self-reflection on advocacy behaviors projected positive attitudes and increased motivation to propose and take actions toward sharing ISA with employees and peers. Key finding 3: the main challenges discovered show that managers need more guidance, increased awareness knowledge, more organizational support, and the creation of a climate that supports advocacy behaviors. Key finding 4: the Action Research workshop contributed to participants learning, and to improvements to information security practices through participants' new behaviors to increase ISA advocacy. Participants reported they learned and used the ISA topics discussed during the workshop with their friends, family, peers, and employees after the workshop. The key thesis findings led to the following recommendations to help organizations foster a climate that supports ongoing advocacy behaviors. The recommended activities include: helping managers understand the importance of their engagement in advocacy behavior; obtaining resources that increase information security awareness and knowledge; planning and sharing activities that promote ISA sharing; and, communication the expectation for advocacy behaviors and the resources available to support sharing information security awareness.
机译:该研究的目的是确定和分析特定的环境和社会条件,这些条件会促使中层管理人员提倡信息安全意识(ISA),并了解接触新的信息安全知识是否会改变他们的行为。使用混合方法行动研究方法,一组管理人员共享了他们的意识知识,倡导行为和影响他们参与信息安全意识倡导的挑战。研讨会后的反馈证实了行动研究研讨会在提高ISA倡导行为方面的有效性。行动研究研讨会为参与者提供了一个机会,可以增加他们的安全知识并建议ISA倡导实践的改进。分为四个讲习班的三十八(38)名经理参加了研究。在研究活动中,我向小组进行了意识知识自我评估调查,该调查捕捉了管理者对他们自己的信息安全知识的看法,样本信息安全意识演示文稿为研讨会带来了背景,以及类似于焦点小组提供了讨论的环境。在这些活动中,管理人员表示建议进行变更,以推动改善ISA的倡导。讲习班的活动以闭幕讨论结束,以寻求管理者承诺根据建议采取行动以改善ISA的宣传。这些学习活动和分享他们的意识,支持了利用行动研究的主要目标。研究结果支持行动研究研讨会,是增加参与者学习,改善ISA倡导实践以及使信息安全性话题社会化的有效工具。信息安全意识学科如下。关键发现1:对信息安全意识中知识的自我反思水平的反馈表明,管理人员没有充分了解ISA内容。关键发现2:对倡导行为的自我反思表明了积极的态度,并增强了提议和采取行动与员工和同事共享ISA的动机。关键发现3:发现的主要挑战表明,经理们需要更多的指导,更多的意识知识,更多的组织支持以及营造支持倡导行为的氛围。关键发现4:行动研究研讨会通过增加参与者对ISA的倡导,通过参与者的新行为为参与者的学习和信息安全实践做出了贡献。参与者报告说,他们在研讨会后与朋友,家人,同龄人和员工一起学习并使用了研讨会期间讨论的ISA主题。论文的主要结论提出了以下建议,以帮助组织营造一种支持正在进行的倡导行为的氛围。建议的活动包括:帮助管理人员了解他们参与倡导行为的重要性;获得可增强信息安全意识和知识的资源;规划和共享活动,以促进ISA共享;传达对倡导行为的期望以及可用于支持共享信息安全意识的资源。

著录项

  • 作者

    Giraldo, Grace.;

  • 作者单位

    Syracuse University.;

  • 授予单位 Syracuse University.;
  • 学科 Information technology.
  • 学位 D.P.S.
  • 年度 2014
  • 页码 329 p.
  • 总页数 329
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号