首页> 外文期刊>Information systems frontiers >The Utility of Information Security Training and Education on Cybersecurity Incidents:An empirical evidence
【24h】

The Utility of Information Security Training and Education on Cybersecurity Incidents:An empirical evidence

机译:信息安全培训和教育网络安全事件的效用:经验证据

获取原文
获取原文并翻译 | 示例
           

摘要

As recent cyber-attacks have been increasing exponentially, the importance of security training for employees also has become growing ever than before. In addition, it is suggested that security training and education be an effective method for discerning cyber-attacks within academia and industries. Despite the importance and the necessity of the training, prior study did not investigate the quantitative utility of security training in an organizational level. Due to the absence of referential studies, many firms are having troubles in making decisions with respect to arranging optimal security training programs with limited security budgets. The main objective of this study is to find out a relationship between cybersecurity training and the number of incidents of organizations. Thus, this study quantified the effectiveness of security training on security incidents as the first study. This research examined the relationship among three main factors; education time, education participants, and outsourcing with numbers of cybersecurity incidents. 7089 firm level data is analyzed through Poisson regression method. Based on analysis results, we found that the negative relationship between security trainings and the occurrence of cybersecurity incidents. This study sheds light on the role of security training and education by suggesting its positive association with reducing the number of incidents in organizations from the quantitative perspective. The result of this study can be used as a referential guide for information security training decision-making procedure in organizations.
机译:随着最近的网络攻击一直在呈指数增长,员工安全培训的重要性也比以前变得越来越大。此外,有人建议安全培训和教育是学术界和行业内的网络攻击的有效方法。尽管培训的重要性和必要性,但事先研究并未调查组织层面安全培训的定量效用。由于缺乏参考研究,许多公司在为安排有限的安全预算中安排最佳安全培训计划而做出麻烦。本研究的主要目标是找出网络安全培训与组织事件的数量之间的关系。因此,本研究量化了安全事故安全事件的有效性。这项研究审查了三个主要因素之间的关系;教育时间,教育参与者以及随着网络安全事故的数量的外包。通过Poisson回归方法分析了7089年的坚固级别数据。根据分析结果,我们发现安全培训与网络安全事件之间的负面关系。本研究通过暗示从量化视角来减少组织中的事件数量的积极协会,阐明了安全培训和教育的作用。本研究的结果可作为组织中信息安全培训决策程序的参照指南。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号