The Experts below are selected from a list of 1863 Experts worldwide ranked by ideXlab platform

Thuy D. Nguyen - One of the best experts on this subject based on the ideXlab platform.

  • a video game for cyber Security Training and awareness
    Computers & Security, 2007
    Co-Authors: B Cone, Cynthia Irvine, Michael F. Thompson, Cynthia E. Irvine, T Nguyen, Michael Thompson, Thuy D. Nguyen
    Abstract:

    Although many of the concepts included in cyber Security awareness Training are universal, such Training often must be tailored to address the policies and requirements of a particular organization. In addition, many forms of Training fail because they are rote and do not require users to think about and apply Security concepts. A flexible, highly interactive video game, CyberCIEGE, is described as a Security awareness tool that can support organizational Security Training objectives while engaging typical users in an engaging Security adventure. The game is now being successfully utilized for information assurance education and Training by a variety of organizations. Preliminary results indicate the game can also be an effective addition to basic information awareness Training programs for general computer users (e.g., annual awareness Training.)

  • SEC - Cyber Security Training and Awareness Through Game Play
    Security and Privacy in Dynamic Environments, 2006
    Co-Authors: B Cone, Michael F. Thompson, Cynthia E. Irvine, Thuy D. Nguyen
    Abstract:

    Although many of the concepts included in staff cyber-Security awareness Training are universal, such Training often must be tailored to address the policies and requirements of a particular organization. In addition, many forms of Training fail because they are rote and do not require users to think about and apply Security concepts. A flexible, highly interactive video game, CyberCIEGE, is described as a Security awareness tool that can support organizational Security Training objectives while engaging typical users in an engaging Security adventure.

  • Cyber Security Training and Awareness Through Game Play
    IFIP TC-11 21st International Information Security, 2006
    Co-Authors: B Cone, Michael F. Thompson, Cynthia E. Irvine, Thuy D. Nguyen
    Abstract:

    Although many of the concepts included in staff cyber-Security awareness Training are universal, such Training often must be tailored to address the policies and requirements of a particular organization. In addition, many forms of Training fail because they are rote and do not require users to think about and apply Security concepts. A flexible, highly interactive video game, CyberCIEGE, is described as a Security awareness tool that can support organizational Security Training objec- tives while engaging typical users in an engaging Security adventure.

B Cone - One of the best experts on this subject based on the ideXlab platform.

  • a video game for cyber Security Training and awareness
    Computers & Security, 2007
    Co-Authors: B Cone, Cynthia Irvine, Michael F. Thompson, Cynthia E. Irvine, T Nguyen, Michael Thompson, Thuy D. Nguyen
    Abstract:

    Although many of the concepts included in cyber Security awareness Training are universal, such Training often must be tailored to address the policies and requirements of a particular organization. In addition, many forms of Training fail because they are rote and do not require users to think about and apply Security concepts. A flexible, highly interactive video game, CyberCIEGE, is described as a Security awareness tool that can support organizational Security Training objectives while engaging typical users in an engaging Security adventure. The game is now being successfully utilized for information assurance education and Training by a variety of organizations. Preliminary results indicate the game can also be an effective addition to basic information awareness Training programs for general computer users (e.g., annual awareness Training.)

  • SEC - Cyber Security Training and Awareness Through Game Play
    Security and Privacy in Dynamic Environments, 2006
    Co-Authors: B Cone, Michael F. Thompson, Cynthia E. Irvine, Thuy D. Nguyen
    Abstract:

    Although many of the concepts included in staff cyber-Security awareness Training are universal, such Training often must be tailored to address the policies and requirements of a particular organization. In addition, many forms of Training fail because they are rote and do not require users to think about and apply Security concepts. A flexible, highly interactive video game, CyberCIEGE, is described as a Security awareness tool that can support organizational Security Training objectives while engaging typical users in an engaging Security adventure.

  • Cyber Security Training and Awareness Through Game Play
    IFIP TC-11 21st International Information Security, 2006
    Co-Authors: B Cone, Michael F. Thompson, Cynthia E. Irvine, Thuy D. Nguyen
    Abstract:

    Although many of the concepts included in staff cyber-Security awareness Training are universal, such Training often must be tailored to address the policies and requirements of a particular organization. In addition, many forms of Training fail because they are rote and do not require users to think about and apply Security concepts. A flexible, highly interactive video game, CyberCIEGE, is described as a Security awareness tool that can support organizational Security Training objec- tives while engaging typical users in an engaging Security adventure.

Elmarie Kritzinger - One of the best experts on this subject based on the ideXlab platform.

  • ICITST - A conceptual analysis of information Security education, information Security Training and information Security awareness definitions
    The 9th International Conference for Internet Technology and Secured Transactions (ICITST-2014), 2014
    Co-Authors: Eric Amankwa, Marianne Loock, Elmarie Kritzinger
    Abstract:

    The importance of information Security education, information Security Training, and information Security awareness in organisations cannot be overemphasised. This paper presents working definitions for information Security education, information Security Training and information Security awareness. An investigation to determine if any differences exist between information Security education, information Security Training and information Security awareness was conducted. This was done to help institutions understand when they need to train or educate employees and when to introduce information Security awareness programmes. A conceptual analysis based on the existing literature was used for proposing working definitions, which can be used as a reference point for future information Security researchers. Three important attributes (namely focus, purpose and method) were identified as the distinguishing characteristics of information Security education, information Security Training and information Security awareness. It was found that these information Security concepts are different in terms of their focus, purpose and methods of delivery.

  • A conceptual analysis of information Security education, information Security Training and information Security awareness definitions
    The 9th International Conference for Internet Technology and Secured Transactions (ICITST-2014), 2014
    Co-Authors: Eric Amankwa, Marianne Loock, Elmarie Kritzinger
    Abstract:

    The importance of information Security education, information Security Training, and information Security awareness in organisations cannot be overemphasised. This paper presents working definitions for information Security education, information Security Training and information Security awareness. An investigation to determine if any differences exist between information Security education, information Security Training and information Security awareness was conducted. This was done to help institutions understand when they need to train or educate employees and when to introduce information Security awareness programmes. A conceptual analysis based on the existing literature was used for proposing working definitions, which can be used as a reference point for future information Security researchers. Three important attributes (namely focus, purpose and method) were identified as the distinguishing characteristics of information Security education, information Security Training and information Security awareness. It was found that these information Security concepts are different in terms of their focus, purpose and methods of delivery.

Shanton Chang - One of the best experts on this subject based on the ideXlab platform.

  • HICSS - An Exploratory Study of Current Information Security Training and Awareness Practices in Organizations
    Proceedings of the 51st Hawaii International Conference on System Sciences, 2020
    Co-Authors: Moneer Alshaikh, Sean B Maynard, Atif Ahmad, Shanton Chang
    Abstract:

    Effective information Security Training and awareness (ISTA) is essential to protect organizational information resources. Our review of industry best-practice guidelines on ISTA exposed two key deficiencies. First, they are presented at a conceptual-level without any empirical evidence of their validity. Second, the guidelines are generic (one size fits all) without consideration of the diversity in organizational contexts where they will be applied. Given these deficiencies in ISTA guidance, this paper reports on the findings of an exploratory study into how ISTA is implemented in different organizational contexts in six organizations. The paper identifies three challenges: the lack of motivational aspects in current ISTA program, the competition for employees’ attention and the difficulty in measuring the effectiveness of ISTA program. Several recommendations and suggestions were outlined to overcome these challenges.

  • an exploratory study of current information Security Training and awareness practices in organizations
    Hawaii International Conference on System Sciences, 2018
    Co-Authors: Moneer Alshaikh, Sean B Maynard, Atif Ahmad, Shanton Chang
    Abstract:

    Effective information Security Training and awareness (ISTA) is essential to protect organizational information resources. Our review of industry best-practice guidelines on ISTA exposed two key deficiencies. First, they are presented at a conceptual-level without any empirical evidence of their validity. Second, the guidelines are generic (one size fits all) without consideration of the diversity in organizational contexts where they will be applied. Given these deficiencies in ISTA guidance, this paper reports on the findings of an exploratory study into how ISTA is implemented in different organizational contexts in six organizations. The paper identifies three challenges: the lack of motivational aspects in current ISTA program, the competition for employees’ attention and the difficulty in measuring the effectiveness of ISTA program. Several recommendations and suggestions were outlined to overcome these challenges.

Mary B. Burns - One of the best experts on this subject based on the ideXlab platform.

  • Simplicity is Bliss: Controlling Extraneous Cognitive Load in Online Security Training to Promote Secure Behavior
    Journal of Organizational and End User Computing, 2013
    Co-Authors: Jeffrey L. Jenkins, Alexandra Durcikova, Mary B. Burns
    Abstract:

    User-initiated Security breaches are common and can be very costly to organizations. Information Security Training can be used as an effective tool to improve users' secure behavior and thus alleviate Security breaches. Via the lens of learning, working memory, and cognitive load theories, this research examines how to improve the effectiveness of Security Training through decreasing extraneous stimuli in the presentation of online Security Training. The authors conducted a realistic laboratory experiment to examine the influence of Training with different levels of extraneous stimuli on secure behavior. They found that Training presented with low levels of extraneous stimuli improved secure behavior more than Training presented with high levels. The results question the effectiveness of elaborate Training programs, and rather suggest that simple, direct Training modules are most effective.

  • HICSS - Forget the Fluff: Examining How Media Richness Influences the Impact of Information Security Training on Secure Behavior
    2012 45th Hawaii International Conference on System Sciences, 2012
    Co-Authors: Jeffrey L. Jenkins, Alexandra Durcikova, Mary B. Burns
    Abstract:

    User-initiated Security breaches are common and can be very costly to organizations. Information Security Training can be used as an effective tool to improve users' secure behavior and thus alleviate Security breaches. Via the lens of learning, media richness, and cognitive load theories, this research examines how to improve the effectiveness of Security Training. We conduct a realistic laboratory experiment to examine the influence of Training with different degrees of media richness on secure behavior. We found that Training with lean media richness improved secure behavior more than Training with highly-rich media. Suggestions for researchers and practitioners are provided.

  • Forget the Fluff: Examining How Media Richness Influences the Impact of Information Security Training on Secure Behavior
    2012 45th Hawaii International Conference on System Sciences, 2012
    Co-Authors: Jeffrey L. Jenkins, Alexandra Durcikova, Mary B. Burns
    Abstract:

    User-initiated Security breaches are common and can be very costly to organizations. Information Security Training can be used as an effective tool to improve users' secure behavior and thus alleviate Security breaches. Via the lens of learning, media richness, and cognitive load theories, this research examines how to improve the effectiveness of Security Training. We conduct a realistic laboratory experiment to examine the influence of Training with different degrees of media richness on secure behavior. We found that Training with lean media richness improved secure behavior more than Training with highly-rich media. Suggestions for researchers and practitioners are provided.