Analyze before you sensitize: Preparation of a targeted ISA training

3Citations
Citations of this article
9Readers
Mendeley users who have this article in their library.

Abstract

This paper describes a procedure to enable the planning of targeted measures to increase the Information Security Awareness (ISA) of employees of an institution. The procedure is practically applied at a German university. With the help of a comprehensive analysis, which is based on findings of social psychology, necessary topics for ISA measures are identified. In addition, reasons are sought for why employees do not conduct information security. The procedure consists of a qualitative phase with interviews and a quantitative phase with a questionnaire. It turned out that the procedure provided many clues to the design of ISA measures. These include organizational and technical measures that can help employees to ensure information-safe behavior. In addition, it was found that there were deviations between the qualitative and quantitative phases and therefore, both phases are necessary. The paper critically discusses the procedure and also addresses the strengths and weaknesses of the analysis.

Cite

CITATION STYLE

APA

Schütz, A. E., Weber, K., & Fertig, T. (2020). Analyze before you sensitize: Preparation of a targeted ISA training. In Proceedings of the Annual Hawaii International Conference on System Sciences (Vol. 2020-January, pp. 6538–6547). IEEE Computer Society. https://doi.org/10.24251/hicss.2020.800

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free