The positive outcomes of information security awareness training in companies - A case study

dc.authorscopusid36348403000
dc.authorscopusid36348997600
dc.authorscopusid57202412803
dc.contributor.authorEmina?ao?lu M.
dc.contributor.authorUçar E.
dc.contributor.authorEren S.
dc.date.accessioned2024-06-12T10:25:02Z
dc.date.available2024-06-12T10:25:02Z
dc.date.issued2009
dc.description.abstractOne of the key factors in successful information security management is the effective compliance of security policies and proper integration of "people", "process" and "technology". When it comes to the issue of "people", this effectiveness can be achieved through several mechanisms, one of which is the security awareness training of employees. However, the outcomes should also be measured to see how successful and effective this training has been for the employees. In this study, an information security awareness project is implemented in a company both by training and by subsequent auditing of the effectiveness and success of this training (which focussed on password usage, password quality and compliance of employees with the password policies of the company). The project was conducted in a Turkish company with 2900 white-collar employees. Each employee took information security training including password usage. Also, there were several supporting awareness campaigns such as educational posters, animations and e-messages on the company Intranet, surveys and simple online quizzes. The project was carried out over a 12 month period and three password security strength audits were made during this period. The results were comparatively and statistically analysed. The results show us the effectiveness of the project and the impact of human awareness on the success of information security management programmes in companies. This study gives us some crucial results, facts and methods that can also be used as a guideline for further similar projects. © 2010 Elsevier Ltd. All rights reserved.en_US
dc.identifier.doi10.1016/j.istr.2010.05.002
dc.identifier.endpage229en_US
dc.identifier.issn1363-4127
dc.identifier.issue4en_US
dc.identifier.scopus2-s2.0-77956620263en_US
dc.identifier.scopusqualityN/Aen_US
dc.identifier.startpage223en_US
dc.identifier.urihttps://doi.org/10.1016/j.istr.2010.05.002
dc.identifier.urihttps://hdl.handle.net/20.500.14551/16161
dc.identifier.volume14en_US
dc.indekslendigikaynakScopusen_US
dc.language.isoenen_US
dc.relation.ispartofInformation Security Technical Reporten_US
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanıen_US
dc.rightsinfo:eu-repo/semantics/closedAccessen_US
dc.subjectInformation Security Management; Password Audit; Password Strength; Password Usage; Security Awareness Campaign; Security Awareness Trainingen_US
dc.subjectInformation Security Managements; Password Audit; Password Strength; Password Usage; Security Awareness; Security Awareness Campaigns; Industrial Management; Personnel; Personnel Training; Network Securityen_US
dc.titleThe positive outcomes of information security awareness training in companies - A case studyen_US
dc.typeArticleen_US

Dosyalar