An Analysis of Information Security Awareness within Home and Work Environments

被引:45
作者
Talib, Shuhaili [1 ]
Clarke, Nathan L. [1 ]
Furnell, Steven M. [1 ]
机构
[1] Univ Plymouth, Ctr Secur Commun & Network Res CSCAN, Plymouth PL4 8AA, Devon, England
来源
FIFTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY: ARES 2010, PROCEEDINGS | 2010年
关键词
information security; information security awareness; security culture; security management;
D O I
10.1109/ARES.2010.27
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
As technology such as the Internet, computers and mobile devices become ubiquitous throughout society, the need to ensure our information remains secure is imperative. Unfortunately, it has long been understood that good security cannot be achieved through technical means alone and a solid understanding of the issues and how to protect yourself is required from users. Whilst many initiatives, programs and strategies have been proposed to improve the level of information security awareness, most have been directed at organizations, with a few national programs focused upon home users. Given people's use of technology is primarily focused upon those two areas: the workplace and home, this paper seeks to understand the knowledge and practice relationship between these environments. Through the survey that was developed, it was identified that the majority of the learning about information security occurred in the workplace, where clear motivations, such as legislation and regulation, existed. It was also found that user's were more than willing to engage with such awareness raising initiatives. From a comparison of practice between work and home environments, it was found that this knowledge and practice obtained at the workplace was transferred to the home environment. Given this positive transferability of knowledge and the willingness to learn about how to remain secure, an opportunity exists to move away from specific organizational awareness programs and to move towards awareness raising strategies that, whilst deployed in the organization, will develop an all-round individual security culture for users independent of the environment within which they are operating.
引用
收藏
页码:196 / 203
页数:8
相关论文
共 32 条
[1]  
ADLAM D, 2009, SOCIAL NETWORKING ID
[2]   A qualitative study of users' view on information security [J].
Albrechtsen, Eirik .
COMPUTERS & SECURITY, 2007, 26 (04) :276-289
[3]  
[Anonymous], SYM INT SEC THREAT R
[4]  
[Anonymous], COMPUTER FRAUD S JUN
[5]  
*BBC, 2007, WEB NETW RISK FRAUD
[6]  
*BERR, 2008, 9 INF SEC BREACH SUR
[7]   A cross-cultural investigation of situational information security awareness programs [J].
Chen, Charlie C. ;
Medlin, B. Dawn ;
Shaw, R.S. .
Information Management and Computer Security, 2008, 16 (04) :360-376
[8]  
CHIA PA, 2002, 6 PAC AS C INF SYST, P731
[9]   A video game for cyber security training and awareness [J].
Cone, Benjamin D. ;
Irvine, Cynthia E. ;
Thompson, Michael F. ;
Nguyen, Thuy D. .
COMPUTERS & SECURITY, 2007, 26 (01) :63-72
[10]  
COOPER MH, 2008, P 36 ANN ACM SIGUCCS