Conference Proceedings

An Exploratory Study of Current Information Security Training and Awareness Practices in Organizations

M alshaikh, S Maynard, A Ahmad, S Chang

Proceedings of the 51st Hawaii International Conference on System Sciences | University of Hawaii Press | Published : 2018


Effective information security training and awareness (ISTA) is essential to protect organizational information resources. Our review of industry best-practice guidelines on ISTA exposed two key deficiencies. First, they are presented at a conceptual-level without any empirical evidence of their validity. Second, the guidelines are generic (one size fits all) without consideration of the diversity in organizational contexts where they will be applied. Given these deficiencies in ISTA guidance, this paper reports on the findings of an exploratory study into how ISTA is implemented in different organizational contexts in six organizations. The paper identifies three challenges: the lack of mot..

View full abstract