[論文レビュー] People Are the Answer to Security: Establishing a Sustainable Information Security Awareness Training (ISAT) Program in Organization
本論文は、Universiti Teknologi Malaysia (UTM) で実施された持続可能な情報セキュリティ意識向上訓練(ISAT)プログラムを提示する。このプログラムは、ウェブベースのトレーニング、月次のテーマ別セッション、キャンパスキャンペーン、外部講師の招待、対象別プレゼンテーションを統合している。本プログラムは、個別化された継続的教育を通じて、ユーザーの認識と行動を効果的に変化させ、組織における長期的なセキュリティレジリエンスを実現するためには、人を中心としたアプローチが不可欠であることを示している。
Educating the users on the essential of information security is very vital and important to the mission of establishing a sustainable information security in any organization and institute. At the University Technology Malaysia (UTM), we have recognized the fact that, it is about time information security should no longer be a lacking factor in productivity, both information security and productivity must work together in closed proximity. We have recently implemented a broad campus information security awareness program to educate faculty member, staff, students and non-academic staff on this essential topic of information security. The program consists of training based on web, personal or individual training with a specific monthly topic, campus campaigns, guest speakers and direct presentations to specialized groups. The goal and the objective are to educate the users on the challenges that are specific to information security and to create total awareness that will change the perceptions of people thinking and ultimately their reactions when it comes to information security. In this paper, we explain how we created and implemented our information security awareness training (ISAT) program and discuss the impediment we encountered along the process. We explore different methods of deliveries such as target audiences, and probably the contents as we believe might be vital to a successful information security program. Finally, we discuss the importance and the flexibility of establishing a sustainable information security training program that could be adopted to meet current and future needs and demands while still relevant to our current users.
研究の動機と目的
- 組織における情報セキュリティ意識の継続的なギャップを是正するため、持続可能でユーザー中心のトレーニングプログラムを構築すること。
- UTMにおける日常的な組織文化に情報セキュリティ教育を統合し、長期的関与と関連性を確保すること。
- 参加率の低さやメッセージの一貫性の欠如といった、ISAT実装における一般的な障壁を克服すること。
- 進化するセキュリティ脅威とユーザーのニーズに適応可能な柔軟でスケーラブルなISATモデルを開発すること。
提案手法
- 教職員、職員、学生、非教職スタッフなど、異なるユーザー層に合わせたウェブベースのモジュールを用いたトレーニングを提供した。
- 長期的な関与を維持するため、月次のテーマ別フォーカスを導入した。
- 主要なセキュリティメッセージの強化と可視性の向上を目的に、キャンパス全体のキャンペーンやイベントを実施した。
- 特定のグループに対して直接プレゼンテーションを行い、ターゲットに合わせた影響をもたらした。
- 各聴衆層に適した現実のセキュリティ課題に基づいてコンテンツを設計した。
- フィードバックループと段階的改善を確立することで、プログラムの適応性と長期的持続可能性を確保した。
実験結果
リサーチクエスチョン
- RQ1どのようにして組織は、ユーザーの関与を長期間にわたり維持できる持続可能な情報セキュリティ意識向上訓練(ISAT)プログラムを構築できるか?
- RQ2ユーザーの情報セキュリティに関する認識や行動を変えるために、どの配信方法が最も効果的か?
- RQ3多様な組織的グループに合わせたISATプログラムをどのようにカスタマイズしつつ、一貫性と関連性を維持できるか?
- RQ4効果的なISAT実装を妨げる制度的・文化的な障壁は何か、そしてそれらをどのように克服できるか?
- RQ5ISATプログラムの長期的持続可能性と適応性を保証するための構造的およびコンテンツ設計の原則は何か?
主な発見
- ISATプログラムは、UTMの多様なユーザー層において、情報セキュリティに関する認識を高め、認識を変化させることに成功した。
- 月次のテーマ別トレーニングセッションは、一回限りのトレーニングや一般的なトレーニングと比較して、継続的な関与を顕著に向上させた。
- キャンパスキャンペーンおよび外部講師のイベントは、可視性の向上とコアなセキュリティメッセージの強化に効果的に寄与した。
- 特定のグループへの対象別プレゼンテーションは、リスクの高い部門において、理解度の向上と行動変容をもたらした。
- プログラムは柔軟性と適応性を示し、新たな脅威やユーザーのニーズの変化に応じて進化できることを実証した。
- ユーザーからのフィードバックは、セキュリティの責任に関する理解の向上と、能動的なセキュリティ行動への態度の明確な変化を示した。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。