The Utility of Information Security Training and Education on Cybersecurity Incidents: An empirical evidence

被引:0
|
作者
Eunkyung Kweon
Hansol Lee
Sangmi Chai
Kyeongwon Yoo
机构
[1] Ewha Womans University,
[2] Sangmyung University,undefined
来源
Information Systems Frontiers | 2021年 / 23卷
关键词
Information security incidents; Information security training; Information security management; Poisson regression analysis;
D O I
暂无
中图分类号
学科分类号
摘要
As recent cyber-attacks have been increasing exponentially, the importance of security training for employees also has become growing ever than before. In addition, it is suggested that security training and education be an effective method for discerning cyber-attacks within academia and industries. Despite the importance and the necessity of the training, prior study did not investigate the quantitative utility of security training in an organizational level. Due to the absence of referential studies, many firms are having troubles in making decisions with respect to arranging optimal security training programs with limited security budgets. The main objective of this study is to find out a relationship between cybersecurity training and the number of incidents of organizations. Thus, this study quantified the effectiveness of security training on security incidents as the first study. This research examined the relationship among three main factors; education time, education participants, and outsourcing with numbers of cybersecurity incidents. 7089 firm level data is analyzed through Poisson regression method. Based on analysis results, we found that the negative relationship between security trainings and the occurrence of cybersecurity incidents. This study sheds light on the role of security training and education by suggesting its positive association with reducing the number of incidents in organizations from the quantitative perspective. The result of this study can be used as a referential guide for information security training decision-making procedure in organizations.
引用
收藏
页码:361 / 373
页数:12
相关论文
共 22 条
  • [1] The Utility of Information Security Training and Education on Cybersecurity Incidents: An empirical evidence
    Kweon, Eunkyung
    Lee, Hansol
    Chai, Sangmi
    Yoo, Kyeongwon
    INFORMATION SYSTEMS FRONTIERS, 2021, 23 (02) : 361 - 373
  • [2] A Conceptual Analysis of Information Security Education, Information Security Training and Information Security Awareness Definitions
    Amankwa, Eric
    Loock, Marianne
    Kritzinger, Elmarie
    2014 9TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2014, : 248 - 252
  • [3] Software Package for Training Users to Respond to Information Security Incidents in Industrial Automated Systems
    Tumbinskaya, M.
    Abzalov, A.
    Davydova, I
    ADVANCES IN AUTOMATION III, 2022, 857 : 439 - 451
  • [4] Reputation Risks through Information Security Incidents
    Eduardovich, Dorokhov Vitaliy
    Vladimirovich, Yankevskiy Alexey
    PROCEEDINGS OF THE 2016 IEEE NORTH WEST RUSSIA SECTION YOUNG RESEARCHERS IN ELECTRICAL AND ELECTRONIC ENGINEERING CONFERENCE (ELCONRUSNW), 2016, : 194 - 198
  • [5] Identifying the Organizational Factors of Information Security Incidents
    Almubark, Abdullah
    Hatanaka, Nobutoshi
    Uchida, Osamu
    Ikeda, Yukiyo
    2015 SECOND INTERNATIONAL CONFERENCE ON COMPUTING TECHNOLOGY AND INFORMATION MANAGEMENT (ICCTIM), 2015, : 7 - 12
  • [6] Information Security in eLearning: A Discussion of Empirical Data on Information Security and eLearning
    Alwi, Najwa Hayaati Mohd
    Fan, Ip-Shing
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON E-LEARNING, 2010, : 282 - 290
  • [7] Study on Information Security Incidents Management in Automobile. Manufacturing Enterprise
    Wu Xiaoyan
    Wang Bei
    PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON INNOVATION AND MANAGEMENT, 2015, : 934 - 937
  • [8] Forecasting of Information Security Related Incidents: Amount of Spam Messages as a Case Study
    Romanov, Anton
    Okamoto, Eiji
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2010, E93B (06) : 1411 - 1421
  • [9] Information Security Training Customized by Risk Profile
    Xu, Shuting
    Meso, Peter
    Ding, Yi
    AMCIS 2016 PROCEEDINGS, 2016,
  • [10] History of Cryptography in Syllabus on Information Security Training
    Zapechnikov, Sergey
    Tolstoy, Alexander
    Nagibin, Sergey
    INFORMATION SECURITY EDUCATION ACROSS THE CURRICULUM, WISE 9, 2015, 453 : 146 - 157