信息系统安全
顺从(心理学)
信息安全
领域(数学)
培训(气象学)
信息技术
战略信息系统
计算机科学
信息系统
管理信息系统
信息管理
知识管理
业务
计算机安全
工程类
心理学
数学
操作系统
社会心理学
物理
纯数学
气象学
电气工程
作者
Ilja Nastjuk,Florian Rampold,Simon Trang,Jose Benitez
标识
DOI:10.1080/0960085x.2024.2359460
摘要
Information security policy (ISP) training plays an important role in enhancing organisational resilience against cyber threats by providing employees with the necessary knowledge and skills to effectively identify, prevent, and respond to security breaches. This research aims to explore how the use of deterrence arguments and threat arguments can enhance the effectiveness of ISP training. We theorise how ISP training affects employees' ISP compliance behaviour by arguing for a transfer of training lens to study the effectiveness of ISP training. The results of our field experiment with triangulated data suggest that the effect of argumentative-enhanced ISP training is twofold. First, employees who participated in enhanced training sessions with deterrence and threat arguments demonstrated superior training outputs after the training, which, in turn, translated into a sustained training outcome three weeks after the training. Second, we also find evidence that threat arguments can reinforce the application of training outputs in the maintenance stage of learned behaviours. With this applied research study, we contribute to the research and practice by providing empirical evidence of the effectiveness of ISP training designs.
科研通智能强力驱动
Strongly Powered by AbleSci AI