“…In praxis and in the literature there exists a great variety of different designs, methods, and nomenclatures of institutional security training activities. Some of the various practices are e.g., the explanation of ISPs(Straub and Welke 1998), periodic newsletters, emails and presentations concerning ISS relevant issues(Spurling 1995, Herath andRao 2009a), ISS workshops and seminars(Thomson and von Solms 1998), providing posters, flyers, and lectures(Crossler and Bélanger 2006), supporting online-- and computer--based learning(Chen et al 2006), or periodic security refresher courses(Hansche 2001a, von Solms and.SETA programs aim to improve organizational information security by increasing employees' knowledge and awareness of potential security risks, policies, and responsibilities. Furthermore, they aim at providing employees with the skills necessary to comply with organizational ISS procedures(Straub and Welke 1998, Whitman et al 2001, Lee and Lee 2002, D'Arcy et al 2009).…”