Lessons Learned from an Information Security Incident: A Practical Recommendation to Involve Employees in Information Security
dc.contributor.author | Tatu, Teodora | |
dc.contributor.author | Ament, Clara | |
dc.contributor.author | Jaeger, Lennart | |
dc.date.accessioned | 2017-12-28T01:55:40Z | |
dc.date.available | 2017-12-28T01:55:40Z | |
dc.date.issued | 2018-01-03 | |
dc.description.abstract | With the increasingly negative impact of information security attacks, measures of information security, which address the weakest link in the information security chain, namely the employee, have become a necessity for today’s business world. One way to improve employees’ - yet limited - information security awareness is to learn from past information security incidents. This study theoretically builds upon the so called involvement theory to extend the existing research on information security awareness. Insights gained from 34 interviews suggest that involvement accompanied with a detailed review of past security incidents has a positive effect on staff’s information security awareness. Employees, directly affected by an information security incident, gain significant information security expertise and knowledge which they can, again, share with their colleagues. Moreover, constructive team work in the light of information security risks as well as an adequate adjustment of security-related measures is fostered. | |
dc.format.extent | 10 pages | |
dc.identifier.doi | 10.24251/HICSS.2018.471 | |
dc.identifier.isbn | 978-0-9981331-1-9 | |
dc.identifier.uri | http://hdl.handle.net/10125/50359 | |
dc.language.iso | eng | |
dc.relation.ispartof | Proceedings of the 51st Hawaii International Conference on System Sciences | |
dc.rights | Attribution-NonCommercial-NoDerivatives 4.0 International | |
dc.rights.uri | https://creativecommons.org/licenses/by-nc-nd/4.0/ | |
dc.subject | Innovative Behavioral IS Security and Privacy Research | |
dc.subject | behavioral information security, information security awareness, information security incident, involvement theory. | |
dc.title | Lessons Learned from an Information Security Incident: A Practical Recommendation to Involve Employees in Information Security | |
dc.type | Conference Paper | |
dc.type.dcmi | Text |
Files
Original bundle
1 - 1 of 1