Matching training to individual learning styles improves information security awareness

被引:14
|
作者
Pattinson, Malcolm [1 ]
Butavicius, Marcus [2 ]
Lillie, Meredith [1 ]
Ciccarello, Beau [1 ]
Parsons, Kathryn [2 ]
Calic, Dragana [2 ]
McCormac, Agata [2 ]
机构
[1] Univ Adelaide, Adelaide, SA, Australia
[2] Def Sci & Technol Grp, Edinburgh, SA, Australia
关键词
Information security; Learning styles; Information security awareness (ISA); Adaptive control framework (ACF); Human aspects of cyber-security (HACS); Human aspects of information security questionnaire (HAIS-Q); CONTROL FRAMEWORK; SOCIAL-INFLUENCE; VALIDATION; ONLINE;
D O I
10.1108/ICS-01-2019-0022
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose This paper aims to introduce the concept of a framework of cyber-security controls that are adaptable to different types of organisations and different types of employees. One of these adaptive controls, namely, the mode of training provided, is then empirically tested for its effectiveness. Design/methodology/approach In total, 1,048 working Australian adults completed the human aspects of the information security questionnaire (HAIS-Q) to determine their individual information security awareness (ISA). This included questions relating to the various modes of cyber-security training they had received and how often it was provided. Also, a set of questions called the cyber-security learning-styles inventory was used to identify their preferred learning styles for training. Findings The extent to which the training that an individual received matched their learning preferences was positively associated with their information security awareness (ISA) level. However, the frequency of such training did not directly predict ISA levels. Research limitations/implications - Further research should examine the influence of matching cyber-security learning styles to training packages more directly by conducting a controlled trial where the training packages provided differ only in the mode of learning. Further research should also investigate how individual tailoring of aspects of an adaptive control framework (ACF), other than training, may improve ISA. Practical implications - If cyber-security training is adapted to the preferred learning styles of individuals, their level of ISA will improve, and therefore, their non-malicious behaviour, whilst using a digital device to do their work, will be safer. Originality/value A review of the literature confirmed that ACFs for cyber-security does exist, but only in terms of hardware and software controls. There is no evidence of any literature on frameworks that include controls that are adaptable to human factors within the context of information security. In addition, this is the first study to show that ISA is improved when cyber-security training is provided in line with an individual's preferred learning style. Similar improvement was not evident when the training frequency was increased suggesting real-world improvements in ISA may be possible without increasing training budgets but by simply matching individuals to their desired mode of training.
引用
收藏
页码:1 / 14
页数:14
相关论文
共 50 条
  • [1] Individual differences and Information Security Awareness
    McCormac, Agata
    Zwaans, Tara
    Parsons, Kathryn
    Calic, Dragana
    Butavicius, Marcus
    Pattinson, Malcolm
    COMPUTERS IN HUMAN BEHAVIOR, 2017, 69 : 151 - 156
  • [2] Gamification of Information Security Awareness and Training
    Gjertsen, Eyvind Garder B.
    Gjaere, Erlend Andreas
    Bartnes, Maria
    Flores, Waldo Rocha
    ICISSP: PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2017, : 59 - 70
  • [3] A Conceptual Analysis of Information Security Education, Information Security Training and Information Security Awareness Definitions
    Amankwa, Eric
    Loock, Marianne
    Kritzinger, Elmarie
    2014 9TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2014, : 248 - 252
  • [4] TRAINING IN SHAPING EMPLOYEE INFORMATION SECURITY AWARENESS
    Stefaniuk, Tomasz
    ENTREPRENEURSHIP AND SUSTAINABILITY ISSUES, 2020, 7 (03): : 1832 - 1846
  • [5] The impact of information richness on information security awareness training effectiveness
    Shaw, R. S.
    Chen, Charlie C.
    Harris, Albert L.
    Huang, Hui-Jou
    COMPUTERS & EDUCATION, 2009, 52 (01) : 92 - 100
  • [6] INFORMATION LITERACY: RESEARCH REFLECTING INDIVIDUAL LEARNING STYLES
    Simonova, Ivana
    EFFICIENCY AND RESPONSIBILITY IN EDUCATION 2013, 2013, : 550 - 556
  • [7] Information Security Awareness: Comparing Perceptions and Training Preferences
    Farooq, Ali
    Kakakhel, Syed Rameez Ullah
    2013 2ND NATIONAL CONFERENCE ON INFORMATION ASSURANCE (NCIA), 2013, : 53 - 57
  • [8] Recommendations for information security awareness training for college students
    Kim, E.B. (ekim@hartford.edu), 1600, JAI Press (22):
  • [9] Gamifying Digital Learning Platform for Information Security Awareness
    Rintanalert, Thanawat
    Luangsodsai, Arthorn
    INNOVATIVE TECHNOLOGIES AND LEARNING, 2021, 13117 : 352 - 364
  • [10] Improving Organisational Information Security Management: The Impact of Training and Awareness
    Waly, Nesren
    Tassabehji, Rana
    Kamala, Mumtaz
    2012 IEEE 14TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS & 2012 IEEE 9TH INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS (HPCC-ICESS), 2012, : 1270 - 1275