首页> 外文会议>Conference on Information Communications Technology and Society >Deliver Security Awareness Training, then Repeat: {Deliver; Measure Efficacy}
【24h】

Deliver Security Awareness Training, then Repeat: {Deliver; Measure Efficacy}

机译:进行安全意识培训,然后重复:{交付;评估功效}

获取原文

摘要

Organisational information security policy contents are disseminated by awareness and training drives. Its success is usually judged based on immediate post-training self-reports which are usually subject to social desirability bias. Such self-reports are generally positive, but they cannot act as a proxy for actual subsequent behaviours. This study aims to formulate and test a more comprehensive way of measuring the efficacy of these awareness and training drives, called ASTUTE. We commenced by delivering security training. We then assessed security awareness (post-training), and followed up by measuring actual behaviours. When we measured actual behaviours after a single delivery of security awareness training, the conversion from intention to behaviour was half of the desired 100%. We then proceeded to deliver the training again, another two times. The repeated training significantly reduced the gap between self-reported intention and actual secure behaviours.
机译:组织信息安全策略的内容由意识和培训驱动力传播。通常根据训练后的即时自我报告来判断其成功,而自我报告通常会受到社会期望偏差的影响。这样的自我报告通常是积极的,但是它们不能代替实际的后续行为。这项研究旨在制定和测试一种更全面的方法来衡量这些意识和培训动力的有效性,称为ASTUTE。我们从提供安全培训开始。然后,我们评估了安全意识(培训后),并通过测量实际行为进行了跟进。当我们在一次安全意识培训后测量实际行为时,从意图到行为的转换是期望的100%的一半。然后,我们又进行了两次培训。反复的训练大大减少了自我报告的意图和实际的安全行为之间的差距。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号