Information Security Training: An Assessment of Effectiveness

The increasing use of technology is the business sector has created the need for information security (IS) training. Training end-users on information security related items assists in the reduction of information risks that organizations encounter in the conduct of business operations. Furthermore, the absence of end-users training in information security will inevitably subject an entity to increased vulnerabilities that can render organizational security technologies and/or measures inept (Chen, Shaw, & Yang, 2006; Siponen, Mahmood, & Pahnila, 2009). A security risk is the likelihood that an incident will occur and organizations commit various resources to mitigate security risks and vulnerabilities (Fenz, Ekelhart, & Neubauer, 2011). However, organizational commitment of resources does not alleviate responsibilities to constantly develop, purchase, or modify systems that assist in reducing security risks. The first section of this article will identify instructions that contribute to improving advance information security techniques. These various security techniques support organizational strategies that reduce information risks. Furthermore, this article will evaluate and compare knowledge-based systems used to reduce information risks. Lastly, the article will present a comparison on systems that are capable of managing information and subsequently provide ways to reduce information risks. Improving Information Security Techniques End-users are the weakest link regarding information security related items (Spears & Barki, 2010). Contrary to the aforementioned belief, Chen et al. (2006) stated the humans are more important than the technology used to reduce risks associated with information security. Arguably, a c... ... middle of paper ...

