[论文解读] People Are the Answer to Security: Establishing a Sustainable Information Security Awareness Training (ISAT) Program in Organization
本文介紹了在马来西亚理工大学(UTM)實施的可持續資訊安全意識培訓(ISAT)計劃,結合網路培訓、每月主題活動、校園宣傳活動、特邀講者演講及針對性講座。該計劃透過量身訂製的持續教育,成功改變使用者對資訊安全的觀感與行為,顯示以人為本的方法對組織長期安全韌性至關重要。
Educating the users on the essential of information security is very vital and important to the mission of establishing a sustainable information security in any organization and institute. At the University Technology Malaysia (UTM), we have recognized the fact that, it is about time information security should no longer be a lacking factor in productivity, both information security and productivity must work together in closed proximity. We have recently implemented a broad campus information security awareness program to educate faculty member, staff, students and non-academic staff on this essential topic of information security. The program consists of training based on web, personal or individual training with a specific monthly topic, campus campaigns, guest speakers and direct presentations to specialized groups. The goal and the objective are to educate the users on the challenges that are specific to information security and to create total awareness that will change the perceptions of people thinking and ultimately their reactions when it comes to information security. In this paper, we explain how we created and implemented our information security awareness training (ISAT) program and discuss the impediment we encountered along the process. We explore different methods of deliveries such as target audiences, and probably the contents as we believe might be vital to a successful information security program. Finally, we discuss the importance and the flexibility of establishing a sustainable information security training program that could be adopted to meet current and future needs and demands while still relevant to our current users.
研究动机与目标
- 為解決組織在資訊安全意識方面的持續缺口,建立一個可持續、以使用者為中心的培訓計劃。
- 將資訊安全教育融入UTM的日常組織文化,確保長期相關性與參與度。
- 克服ISAT實施常見障礙,如參與度低與訊息不一致。
- 發展一個彈性、可擴展的ISAT模式,能適應不斷演變的安全威脅與使用者需求。
提出的方法
- 透過針對不同使用者群組(包括教職員、行政人員、學生及非學術人員)量身訂製的網路模組提供培訓。
- 實施每月主題聚焦,以維持相關性並長期維持使用者興趣。
- 舉辦全校性宣傳活動與活動,強化關鍵安全訊息並提升可見度。
- 邀請講者演講並針對特定群體提供直接講座,以達成針對性影響。
- 內容設計基於與各受眾群組相關的現實世界安全挑戰。
- 建立反饋迴圈與迭代改進機制,確保計畫具備彈性與長期可持續性。
实验结果
研究问题
- RQ1組織應如何建立一個可持續的資訊安全意識培訓(ISAT)計畫,以長期維持使用者參與?
- RQ2哪些傳播方式最有效於改變使用者對資訊安全的觀感與行為?
- RQ3如何針對多樣化的組織群體量身訂製ISAT計畫,同時維持一致性與相關性?
- RQ4哪些制度與文化障礙會阻礙ISAT的有效實施?又該如何克服?
- RQ5哪些結構與內容設計原則能確保ISAT計畫的長期可持續性與適應性?
主要发现
- ISAT計畫成功提升UTM各類使用者群組對資訊安全的意識,並改變其觀感。
- 每月主題培訓課程顯著提升持續參與度,優於一次性或通用性培訓。
- 校園宣傳活動與講者演講有效提升可見度,並強化核心安全訊息。
- 針對高風險部門的專題講座,顯著提升理解度與行為改變。
- 計畫展現高度彈性與適應性,能隨新威脅與使用者需求演變。
- 使用者反饋顯示對安全責任的理解有所提升,且對主動安全行為的態度出現可測量的轉變。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。