2014Journal of the Association for Information SystemsRequires access

Information Systems Security Training in Organizations: Andragogical Perspective

Patrick Offor, Gurvirender Tejay

Open publisher page 2 citations

Abstract

Organizations continue to suffer information systems (IS) security leaks, despite current research efforts by academia and practitioners to improve organizations’ security compliance. IS security training has been identified as a major IS security threats mitigation strategy because personnel and administrative issues were recognized as major gaps between IS security threats and their countermeasures. Lack of employees’ awareness has also been identified as a major obstacle to effective IS security posture. In addition, employee noncompliance with IS security policies and insider threats were acknowledged as fundamental security concerns for organizations. We argue that IS security awareness training and education are fundamentally important to an organization’s ability to ensure policy compliance. Therefore, an effective IS security design and education, which are learner-centered, task-centered, problem-centered will be more relevant to an organization; hence, the adoption of Adult Learning Theory to examine the phenomenon.

About this research paper

What this paper is about

Organizations continue to suffer information systems (IS) security leaks, despite current research efforts by academia and practitioners to improve organizations’ security compliance. IS security training has been identified as a major IS security threats mitigation strategy because personnel and administrative issues were recognized as major gaps between IS security threats and their countermeasures. Lack of employees’ awareness has also been identified as a major obstacle to effective IS security posture. In addition, employee noncompliance with IS security policies and insider threats were acknowledged as fundamental security concerns for organizations. We argue that IS security awareness training and education are fundamentally important to an organization’s ability to ensure policy compliance. Therefore, an effective IS security design and education, which are learner-centered, task-centered, problem-centered will be more relevant to an organization; hence, the adoption of Adult Learning Theory to examine the phenomenon.

Why it matters

OpenAlex reports 2 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Organizations continue to suffer information systems (IS) security leaks, despite current research efforts by academia and practitioners to improve organizations’ security compliance. IS security training has been identified as a major IS security threats mitigation strategy because personnel and administrative issues were recognized as major gaps between IS security threats and their countermeasures. Lack of employees’ awareness has also been identified as a major obstacle to effective IS security posture. In addition, employee noncompliance with IS security policies and insider threats were acknowledged as fundamental security concerns for organizations. We argue that IS security awareness training and education are fundamentally important to an organization’s ability to ensure policy compliance. Therefore, an effective IS security design and education, which are learner-centered, task-centered, problem-centered will be more relevant to an organization; hence, the adoption of Adult Learning Theory to examine the phenomenon.

Key concepts: Insider, Information security standards, Obstacle, Critical security studies, Security awareness, Security through obscurity, Information security, Security information and event management

Related papers

Back to paper searchBrowse research topicsOriginal source
Information Systems Security Training in Organizations: Andragogical Perspective — Research Paper | ScholarLens