2021
DOI: 10.1016/j.cose.2021.102267
|View full text |Cite
|
Sign up to set email alerts
|

Enhancing employees information security awareness in private and public organisations: A systematic literature review

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

2
70
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
5
3

Relationship

1
7

Authors

Journals

citations
Cited by 122 publications
(72 citation statements)
references
References 65 publications
2
70
0
Order By: Relevance
“…This is in line with a study conducted in public organizations in Greece where the findings showed that the level of employee information security awareness is low and needs to be raised (Loukis and Spinellis, 2001). Furthermore, other previous studies also confirm the lack of information security awareness among employees (Chan and Mubarak, 2012;Mataracioglu and Ozkan, 2011;Khando et al, 2021) and highlight the fact that the human factor is one of the most common reasons for security breaches in organizations due to the employees' lack of information security awareness (Soomro et al, 2016;Spears and Barki, 2010;Parsons et al, 2014). Information where loss of confidentiality/integrity/availability leads to a minor damage to external actors (companies, other municipalities, regions, other authorities).…”
Section: Theoretical Contributionsupporting
confidence: 90%
“…This is in line with a study conducted in public organizations in Greece where the findings showed that the level of employee information security awareness is low and needs to be raised (Loukis and Spinellis, 2001). Furthermore, other previous studies also confirm the lack of information security awareness among employees (Chan and Mubarak, 2012;Mataracioglu and Ozkan, 2011;Khando et al, 2021) and highlight the fact that the human factor is one of the most common reasons for security breaches in organizations due to the employees' lack of information security awareness (Soomro et al, 2016;Spears and Barki, 2010;Parsons et al, 2014). Information where loss of confidentiality/integrity/availability leads to a minor damage to external actors (companies, other municipalities, regions, other authorities).…”
Section: Theoretical Contributionsupporting
confidence: 90%
“…Relevant research stated that an appropriate level of information security in organizations requires a holistic, multidimensional approach (Yildirim, 2016), (Khando et al , 2021) composed of different major components. Panguluri et al (2017) report that the main components are technical measures, people and processes.…”
Section: Resultsmentioning
confidence: 99%
“…As noticed, different authors with different complexity and depth describe the concept of information security culture, but no matter of their approaches, it is possible to notice that all of them emphasize the importance of consistent behaviour of people against the rules defined in security policies. In that capacity, human dimension of information security cannot be fully addressed by technical and management measures (Chang and Lin, 2007) (Khando et al , 2021). The objective of information security culture is to protect information assets by promoting cautious and secure employee behaviour, i.e.…”
Section: Theoretical Background and Motivationmentioning
confidence: 99%
See 1 more Smart Citation
“…One potential way to continue to increase employees' 1) ability to detect and 2) motivation to report phishing emails might be through the gamification of the mock phishing campaign experience. The addition of gaming elements to non-gaming situations in this and other cyber-related contexts has been explored (Francia et al, 2014;Gjertsen et al, 2017;Emm, 2021;Khando et al, 2021). For example, gamification has demonstrated promise in the education of normal users regarding password security (Scholefield and Shepherd, 2019), and gamified systems can increase motivation to comply with security policy and reduce mock phishing failures, significantly outperforming training provided via email (Silic and Lowry, 2020).…”
Section: Background On Phishingmentioning
confidence: 99%