Influence of Awareness and Training on Cyber Security

被引:49
|
作者
McCrohan, Kevin [1 ]
Engel, Kathryn [2 ]
Harvey, James [1 ]
机构
[1] George Mason Univ, Sch Management, Enterprise Hall 135 MSN 5F4, Fairfax, VA 22030 USA
[2] Aptima Inc, Washington, DC USA
关键词
behavior change; computer security; password usage; security awareness training; training experiments;
D O I
10.1080/15332861.2010.487415
中图分类号
F [经济];
学科分类号
02 ;
摘要
This article presents the results of a study to determine the impact of a cyber threat education and awareness intervention on changes in user security behavior. Subjects were randomly assigned to one of two introductory lectures about cyber threats due to poor password management. The low-information condition was based on very general background information on passwords and computer security, while the high-information condition included very detailed and specific information on the threats to subjects' use of e-commerce. The pre/post-treatment design was a single, between-subjects factor (information level-low/high), repeated measures study, with password strength at Time 1 and password strength at Time 2 used to measure change in security behavior over a period of two weeks. The study found that at Time 1, participants possessed no significant differences in the strength of their passwords. Two weeks later, the password strength of the participants in the low-information condition was not statistically different than their initial levels, while subjects in the high-information condition demonstrated password ratings 36 percent stronger (t = 17.0, p = .000). It is concluded that when users were educated of the threats to e-commerce and trained about proper security practices, their behavior could be changed to enhance online security for themselves and the firms where they are employed.
引用
收藏
页码:23 / 41
页数:19
相关论文
共 50 条
  • [31] Enhancing Cyber Security Awareness with Mobile Games
    Alotaibi, F.
    Furnell, S.
    Stengel, I.
    Papadaki, M.
    2017 12TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2017, : 129 - 134
  • [32] Reviewing Cyber Security Social Engineering Training and Awareness Programs-Pitfalls and Ongoing Issues
    Aldawood, Hussain
    Skinner, Geoffrey
    FUTURE INTERNET, 2019, 11 (03)
  • [33] Employee Cyber-Security Awareness Training (CSAT) Programs in Ireland's Financial Institutions
    Jouaibi, Reda
    Gaylard, Aisling Keenan
    Lee, Brian
    2022 CYBER RESEARCH CONFERENCE - IRELAND (CYBER-RCI), 2022, : 87 - 90
  • [34] A Multi-Tier Approach to Cyber Security Education, Training, and Awareness in the Undergraduate Curriculum (CSETA)
    Swain, Nikunja
    2014 ASEE ANNUAL CONFERENCE, 2014,
  • [35] Community security awareness training
    Endicott-Popovsky, B
    Orton, I
    Bailey, K
    Frincke, D
    Proceedings from the Sixth Annual IEEE Systems, Man and Cybernetics Information Assurance Workshop, 2005, : 373 - 379
  • [36] The challenge of security awareness training
    Comput. Fraud Secur., 2009, 10 (15-16):
  • [37] EXCON teams in cyber security training
    Ostby, Grethe
    Lovell, Kieren Nicolas
    Katt, Basel
    2019 6TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND COMPUTATIONAL INTELLIGENCE (CSCI 2019), 2019, : 14 - 19
  • [38] Practical Cyber Security Training Exercises
    Wahsheh, Luay A.
    Mekonnen, Biruk
    2019 6TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND COMPUTATIONAL INTELLIGENCE (CSCI 2019), 2019, : 48 - 53
  • [39] Discussion on Cyber Security Awareness and Awareness Model Building Based on Connectionism
    Li Jixing
    Wang Yu
    Qi Bin
    PROCEEDINGS OF 2018 IEEE 4TH INFORMATION TECHNOLOGY AND MECHATRONICS ENGINEERING CONFERENCE (ITOEC 2018), 2018, : 259 - 263
  • [40] Organization and training of a Cyber security team
    Dodge, RC
    Ragsdale, DJ
    Reynolds, C
    2003 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN AND CYBERNETICS, VOLS 1-5, CONFERENCE PROCEEDINGS, 2003, : 4311 - 4316