@article{ART002327920},
author={Bora Kim and Lee, Jong-Won and Beomsoo Kim},
title={Effect of Information Security Training and Services on Employees’ Compliance to Security Policies},
journal={Informatization Policy},
issn={1598-3498},
year={2018},
volume={25},
number={1},
pages={99-114},
doi={10.22693/NIAIP.2018.25.1.099}
TY - JOUR
AU - Bora Kim
AU - Lee, Jong-Won
AU - Beomsoo Kim
TI - Effect of Information Security Training and Services on Employees’ Compliance to Security Policies
JO - Informatization Policy
PY - 2018
VL - 25
IS - 1
PB - NIA
SP - 99
EP - 114
SN - 1598-3498
AB - In the past, organizations tended to focus on physical and technical aspects in managing corporate's information security (IS), rather than the aspect of human resources related to IS. Recently, increasing security incidents caused by organization members raise the issue of how to improve employees' compliance to security policies.
This study conducted a field experiment to examine the effect of security awareness training and technical security services on employee's security behaviors. In Study 1, the number of spam opening cases were measured right after the IS training and re-measured three months later. In Study 2, a spam warning message was provided and then the number of employees’ spam opening cases were measured to find out the effect of security services. It was found that both the IS training and the technical IS service were effective; they significantly decreased spam opening rates. However, the training effect did not last longer than three months. These findings suggest that organizations need to consider providing regular training programs and supplementary technical services to improve employees' compliance to security policies.
KW - information security;security awareness training;technical security service;security policycompliance;field experiment;spam
DO - 10.22693/NIAIP.2018.25.1.099
ER -
Bora Kim, Lee, Jong-Won and Beomsoo Kim. (2018). Effect of Information Security Training and Services on Employees’ Compliance to Security Policies. Informatization Policy, 25(1), 99-114.
Bora Kim, Lee, Jong-Won and Beomsoo Kim. 2018, "Effect of Information Security Training and Services on Employees’ Compliance to Security Policies", Informatization Policy, vol.25, no.1 pp.99-114. Available from: doi:10.22693/NIAIP.2018.25.1.099
Bora Kim, Lee, Jong-Won, Beomsoo Kim "Effect of Information Security Training and Services on Employees’ Compliance to Security Policies" Informatization Policy 25.1 pp.99-114 (2018) : 99.
Bora Kim, Lee, Jong-Won, Beomsoo Kim. Effect of Information Security Training and Services on Employees’ Compliance to Security Policies. 2018; 25(1), 99-114. Available from: doi:10.22693/NIAIP.2018.25.1.099
Bora Kim, Lee, Jong-Won and Beomsoo Kim. "Effect of Information Security Training and Services on Employees’ Compliance to Security Policies" Informatization Policy 25, no.1 (2018) : 99-114.doi: 10.22693/NIAIP.2018.25.1.099
Bora Kim; Lee, Jong-Won; Beomsoo Kim. Effect of Information Security Training and Services on Employees’ Compliance to Security Policies. Informatization Policy, 25(1), 99-114. doi: 10.22693/NIAIP.2018.25.1.099
Bora Kim; Lee, Jong-Won; Beomsoo Kim. Effect of Information Security Training and Services on Employees’ Compliance to Security Policies. Informatization Policy. 2018; 25(1) 99-114. doi: 10.22693/NIAIP.2018.25.1.099
Bora Kim, Lee, Jong-Won, Beomsoo Kim. Effect of Information Security Training and Services on Employees’ Compliance to Security Policies. 2018; 25(1), 99-114. Available from: doi:10.22693/NIAIP.2018.25.1.099
Bora Kim, Lee, Jong-Won and Beomsoo Kim. "Effect of Information Security Training and Services on Employees’ Compliance to Security Policies" Informatization Policy 25, no.1 (2018) : 99-114.doi: 10.22693/NIAIP.2018.25.1.099