Information Systems Security Training in Organizations: Andragogical Perspective
Patrick Offor, Gurvirender Tejay
Abstract
Patrick Offor, Gurvirender Tejay
Abstract
Organizations continue to suffer information systems (IS) security leaks, despite current research efforts by academia and practitioners to improve organizations’ security compliance. IS security training has been identified as a major IS security threats mitigation strategy because personnel and administrative issues were recognized as major gaps between IS security threats and their countermeasures. Lack of employees’ awareness has also been identified as a major obstacle to effective IS security posture. In addition, employee noncompliance with IS security policies and insider threats were acknowledged as fundamental security concerns for organizations. We argue that IS security awareness training and education are fundamentally important to an organization’s ability to ensure policy compliance. Therefore, an effective IS security design and education, which are learner-centered, task-centered, problem-centered will be more relevant to an organization; hence, the adoption of Adult Learning Theory to examine the phenomenon.
OpenAlex reports 2 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Organizations continue to suffer information systems (IS) security leaks, despite current research efforts by academia and practitioners to improve organizations’ security compliance. IS security training has been identified as a major IS security threats mitigation strategy because personnel and administrative issues were recognized as major gaps between IS security threats and their countermeasures. Lack of employees’ awareness has also been identified as a major obstacle to effective IS security posture. In addition, employee noncompliance with IS security policies and insider threats were acknowledged as fundamental security concerns for organizations. We argue that IS security awareness training and education are fundamentally important to an organization’s ability to ensure policy compliance. Therefore, an effective IS security design and education, which are learner-centered, task-centered, problem-centered will be more relevant to an organization; hence, the adoption of Adult Learning Theory to examine the phenomenon.
Key concepts: Insider, Information security standards, Obstacle, Critical security studies, Security awareness, Security through obscurity, Information security, Security information and event management