An Exploratory Study of the Effects of Knowledge Sharing Methods on Cyber Security Practice

被引:7
作者
Hiep Cong Pham [1 ]
Ulhaq, Irfan [1 ]
Minh Nhat Nguyen [1 ]
Nkhoma, Mathews [1 ]
机构
[1] RMIT Univ Vietnam, Ho Chi Minh City, Vietnam
关键词
knowledge sharing; social media; cyber security; security compliance; INFORMATION SECURITY; SELF-EFFICACY; ORGANIZATIONAL KNOWLEDGE; POLICY COMPLIANCE; MODEL; COMMUNITIES; PERFORMANCE; BEHAVIORS; APPEALS; SYSTEMS;
D O I
10.3127/ajis.v25i0.2177
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In a networked global economy, cyber security threats have accelerated at an enormous rate. The security infrastructure at organisational and national levels are often ineffective against these threats. As a result, academics have focused their research on information security risks and technical perspectives to enhance human-related security measures. To further extend this trend of research, this study examines the effects of three knowledge sharing methods on user security practices: security training, social media communication, and local security experts (non-IT staff). The study adopts a phenomenological method employing in-depth focus group interviews with 30 participants from eight organisations located in Ho Chi Minh city, Vietnam. The study expands on understanding factors contributing to self-efficacy and security practice through various knowledge sharing channels. Current methods of periodical training and broadcast emails were found to be less effective in encouraging participants to develop security self-efficacy and were often ignored. Security knowledge sharing through social media and local experts were identified as supplementary methods in maintaining employees' security awareness. In particular, social media is suggested as a preferred channel for disseminating urgent security alerts and seeking peer advice. Local security experts are praised for providing timely and contextualised security advice where member trust is needed. This study suggests that provisions of contemporary channels for security information and knowledge sharing between organisations and employees can gain regular attention from employees, hence leading to more effective security practices.
引用
收藏
页码:1 / 23
页数:23
相关论文
共 68 条
[1]  
Aloul Fadi A., 2012, Journal of Advances in Information Technology, V3, P176, DOI 10.4304/jait.3.3.176-183
[2]  
[Anonymous], 2016, J BUS ETHICS, DOI [DOI 10.1007/S10551-014-2346-X, DOI 10.1007/s10551-014-2346-x]
[3]   Information Security management: A human challenge? [J].
Department of Informatics and Sensors, Cranfield University, Swindon, SN6 8LA, United Kingdom .
Inf Secur Tech Rep, 2008, 4 (195-201) :195-201
[4]  
Ashworth P., 1999, Qualitative Studies in Education, V12, P707, DOI [10.1080/095183999235845, DOI 10.1080/095183999235845]
[5]   Don't Even Think About It! The Effects of Antineutralization, Informational, and Normative Communication on Information Security Compliance [J].
Barlow, Jordan B. ;
Warkentin, Merrill ;
Ormond, Dustin ;
Dennis, Alan R. .
JOURNAL OF THE ASSOCIATION FOR INFORMATION SYSTEMS, 2018, 19 (08) :689-715
[6]  
Bauman S., 2018, REDUCING CYBERBULLYI, P225, DOI [10.1016/B978-0-12-811423-0.00017-1, DOI 10.1016/B978-0-12-811423-0.00017-1]
[7]  
Brandl D., 2012, CONTROL ENG, V59, P8
[8]   Fear, guilt, and shame appeals in social marketing [J].
Brennan, Linda ;
Binney, Wayne .
JOURNAL OF BUSINESS RESEARCH, 2010, 63 (02) :140-146
[9]  
Brown JS, 2000, HARVARD BUS REV, V78, P73
[10]  
Bulgurcu B, 2010, MIS QUART, V34, P523