Exploring cybersecurity awareness and training strategies to prot

Khám phá chiến lược nâng cao nhận thức & đào tạo an ninh mạng. Xây dựng môi trường số an toàn.

Trường ĐH
Walden University
Chuyên ngành

Information Technology

Tác giả

Luan An

Thể loại

Luận án tiến sĩ

Năm xuất bản

Số trang

195

Thời gian đọc

30 phút

Lượt xem

0

Lượt tải

0

Phí lưu trữ

50 Point

Tổng quan nhanh

Chủ đề:
Nâng cao nhận thức bảo mật hệ thống thông tin
Số trang:
195 trang
Trường:
Walden University
Chuyên ngành:
Information Technology
Tác giả:
Năm:

Tóm tắt nội dung luận án

I.Nâng cao nhận thức bảo mật hệ thống thông tin

Các chương trình giáo dục, đào tạo và nhận thức về an ninh (SETA) không hiệu quả gây ra những tổn thất đáng kể. Chúng góp phần vào việc hệ thống thông tin và dữ liệu của các tổ chức bị xâm phạm. Người dùng thực hiện các hành động không phù hợp do thiếu nhận thức. Điều này có thể dẫn đến nhiều hậu quả nghiêm trọng. Các hậu quả bao gồm hậu quả pháp lý, tiền phạt nặng. Tổ chức cũng phải đối mặt với thiệt hại về danh tiếng. An ninh quốc gia có thể bị ảnh hưởng tiêu cực. Các hành vi tội phạm cũng có thể xảy ra. Nâng cao nhận thức về an ninh mạng là điều cần thiết để bảo vệ tài sản thông tin. Nó giúp duy trì sự toàn vẹn và bảo mật của dữ liệu. Các tổ chức cần giải quyết vấn đề nhận thức yếu kém. Việc này là bước đầu tiên để tăng cường khả năng phòng thủ mạng. Chương trình SETA mạnh mẽ tạo ra một nền văn hóa an ninh. Nền văn hóa này khuyến khích hành vi người dùng có trách nhiệm. Nó bảo vệ các hệ thống quan trọng khỏi các mối đe dọa ngày càng tăng. Thách thức nằm ở việc phát triển và triển khai các chương trình SETA thực sự hiệu quả. Các chương trình này phải thu hút và giáo dục người dùng. Mục tiêu cuối cùng là giảm thiểu rủi ro do lỗi của con người.

1.1. Tác động của chương trình SETA kém hiệu quả

Chương trình SETA không hiệu quả dẫn đến nhiều rủi ro. Các hệ thống thông tin tổ chức thường xuyên bị xâm phạm. Dữ liệu nhạy cảm dễ bị tấn công. Người dùng mắc lỗi do thiếu kiến thức bảo mật. Các hành vi bất cẩn tạo ra lỗ hổng. Những lỗ hổng này khai thác bởi các tác nhân đe dọa. Hậu quả trực tiếp là mất mát dữ liệu. Hoạt động kinh doanh bị gián đoạn. Các cuộc tấn công mạng thành công thường bắt nguồn từ lỗi của con người. Việc thiếu đào tạo và nhận thức làm trầm trọng thêm vấn đề này. Điều này làm cho các tổ chức dễ bị tổn thương hơn. Các giải pháp bảo mật kỹ thuật không đủ để bảo vệ hoàn toàn. Con người vẫn là mắt xích yếu nhất trong chuỗi an ninh mạng. Cần có các chương trình giáo dục liên tục và có mục tiêu. Chúng giúp giảm thiểu các rủi ro này.

1.2. Hậu quả đối với an ninh tổ chức và dữ liệu

Các chương trình an ninh yếu kém có hậu quả sâu rộng. Các tổ chức phải đối mặt với tiền phạt và hình phạt pháp lý. Các quy định bảo vệ dữ liệu ngày càng nghiêm ngặt. Việc không tuân thủ dẫn đến chi phí đáng kể. Uy tín của tổ chức cũng bị tổn hại nghiêm trọng. Khách hàng mất lòng tin. Đối tác kinh doanh có thể rút lui. An ninh quốc gia cũng có thể bị ảnh hưởng. Các hệ thống quan trọng bị tấn công. Dữ liệu nhạy cảm bị rò rỉ. Điều này gây ra mối đe dọa lớn. Tội phạm mạng khai thác các lỗ hổng. Họ thực hiện các hành vi bất hợp pháp. Bảo vệ dữ liệu và hệ thống thông tin là ưu tiên hàng đầu. Việc này đảm bảo hoạt động kinh doanh liên tục. Nó duy trì niềm tin của công chúng. Đầu tư vào SETA hiệu quả là cần thiết. Nó giúp ngăn chặn những hậu quả này. Các biện pháp phòng ngừa chủ động mang lại lợi ích lâu dài.

II.Xây dựng chiến lược đào tạo an ninh mạng hiệu quả

Nghiên cứu này khám phá các chiến lược đào tạo an ninh mạng. Nó tìm hiểu cách các nhà lãnh đạo CNTT triển khai thành công các chương trình SETA. Mục đích là cung cấp thông tin quý giá cho các tổ chức. Việc này giúp họ tăng cường khả năng phòng thủ mạng. Nghiên cứu dựa trên lý thuyết nhận thức xã hội. Lý thuyết này nhấn mạnh tầm quan trọng của việc học hỏi từ kinh nghiệm. Nó cũng đề cao sự tương tác xã hội trong việc định hình hành vi. Các chương trình SETA cần được thiết kế dựa trên nguyên tắc này. Chúng phải thúc đẩy sự tự tin và hiệu quả của người dùng. Người dùng cần hiểu rõ vai trò của họ trong việc bảo vệ thông tin. Việc này tạo ra một môi trường an toàn hơn. Các chiến lược hiệu quả không chỉ truyền đạt kiến thức. Chúng còn thay đổi hành vi thực tế. Điều này đảm bảo an toàn cho hệ thống và dữ liệu. Nghiên cứu tập trung vào việc xác định các phương pháp thực hành tốt nhất. Các phương pháp này đã chứng minh hiệu quả trong môi trường thực tế.

2.1. Mục tiêu nghiên cứu và cơ sở lý thuyết

Mục đích chính của nghiên cứu là khám phá các chiến lược. Các chiến lược này được các nhà lãnh đạo CNTT ngành khách sạn sử dụng. Họ triển khai các chương trình SETA thành công. Nghiên cứu được thực hiện dưới hình thức nghiên cứu định tính. Nó sử dụng phương pháp nghiên cứu tình huống đa trường hợp. Cơ sở lý thuyết của nghiên cứu là lý thuyết nhận thức xã hội. Lý thuyết này cho rằng hành vi con người bị ảnh hưởng bởi nhận thức cá nhân. Nó cũng bị tác động bởi môi trường và các yếu tố hành vi. Trong ngữ cảnh an ninh mạng, lý thuyết này rất phù hợp. Nó giải thích tại sao người dùng thực hiện các hành động bảo mật nhất định. Nó cũng giải thích cách các chương trình đào tạo có thể thay đổi hành vi đó. Việc hiểu rõ các yếu tố này giúp thiết kế SETA hiệu quả hơn. Các chương trình SETA phải cân nhắc đến yếu tố tâm lý xã hội. Điều này đảm bảo hiệu quả lâu dài trong việc bảo vệ hệ thống thông tin và dữ liệu.

2.2. Phương pháp luận nghiên cứu định tính

Nghiên cứu áp dụng phương pháp nghiên cứu tình huống đa trường hợp định tính. Bốn tổ chức trong ngành khách sạn ở Hampton Roads, Virginia, tham gia. Các tổ chức này cung cấp dữ liệu quan trọng. Đối tượng tham gia là sáu nhà lãnh đạo CNTT. Họ đến từ các tổ chức này. Dữ liệu được thu thập thông qua phỏng vấn qua điện thoại và hội nghị truyền hình. Ba mươi mốt tài liệu liên quan đến chương trình SETA cũng được phân tích. Phân tích dữ liệu sử dụng phương pháp phân tích chủ đề. Phương pháp này giúp xác định các mô hình và chủ đề chính. Kết quả phân tích dẫn đến ba chủ đề nổi bật. Các chủ đề này cung cấp cái nhìn sâu sắc. Chúng cho thấy các chiến lược thành công. Các chiến lược này nhằm mục đích tăng cường nhận thức an ninh mạng. Chúng cũng cải thiện hành vi bảo mật của nhân viên. Phương pháp này đảm bảo tính toàn diện. Nó mang lại hiểu biết sâu sắc về các thực tiễn tốt nhất.

III.Các yếu tố then chốt tăng cường an ninh mạng

Nghiên cứu đã xác định ba chủ đề chính. Các chủ đề này là yếu tố then chốt để tăng cường an ninh mạng. Chúng chỉ ra các chiến lược hiệu quả cho chương trình SETA. Các chương trình cần liên tục, phù hợp và dựa trên rủi ro thực tế. Việc truyền đạt kỳ vọng rõ ràng cũng rất quan trọng. Hành động thích hợp cần được thực hiện dựa trên hành vi của nhân viên. Những yếu tố này tạo thành một khuôn khổ toàn diện. Chúng giúp các tổ chức xây dựng khả năng phòng thủ mạng mạnh mẽ. Việc này không chỉ giới hạn ở công nghệ. Nó còn tập trung vào yếu tố con người. Con người là tuyến phòng thủ đầu tiên. Việc hiểu và áp dụng các chủ đề này sẽ giảm thiểu đáng kể rủi ro. Rủi ro liên quan đến vi phạm an ninh do lỗi người dùng sẽ giảm.

3.1. Đào tạo liên tục phù hợp với các mối đe dọa

Chủ đề đầu tiên nhấn mạnh sự cần thiết của đào tạo liên tục và phù hợp. Các chương trình nhận thức và đào tạo cần được thực hiện nhất quán. Chúng không phải là sự kiện một lần. Nội dung đào tạo phải liên quan trực tiếp đến các mối đe dọa. Các mối đe dọa này mà tổ chức và nhân viên đối mặt. Nó cần được cập nhật thường xuyên. Mối đe dọa mạng luôn phát triển. Các chiến thuật tấn công liên tục thay đổi. Đào tạo liên tục giúp nhân viên cập nhật kiến thức mới nhất. Đào tạo phù hợp đảm bảo thông tin hữu ích. Nó có thể áp dụng vào công việc hàng ngày. Điều này tạo ra một văn hóa cảnh giác. Nó giúp nhân viên chủ động nhận diện và phản ứng. Họ phản ứng với các mối đe dọa tiềm ẩn. Việc đầu tư vào các chương trình đào tạo định kỳ là rất quan trọng. Nó giúp duy trì một lực lượng lao động có ý thức bảo mật cao.

3.2. Nhận thức dựa trên mối đe dọa lỗ hổng và rủi ro

Chủ đề thứ hai tập trung vào nhận thức dựa trên rủi ro. Các chương trình đào tạo và nhận thức cần dựa trên phân tích thực tế. Phân tích này về các mối đe dọa, lỗ hổng và rủi ro. Các tổ chức phải xác định rõ ràng. Họ cần biết mình đang bảo vệ cái gì. Họ cũng cần biết đang bảo vệ khỏi ai. Các khóa đào tạo nên giải quyết các lỗ hổng cụ thể. Các lỗ hổng này có thể tồn tại trong hệ thống. Chúng cũng có thể tồn tại trong hành vi của nhân viên. Giáo dục nhân viên về các rủi ro cụ thể là rất quan trọng. Họ cần hiểu cách hành động của họ ảnh hưởng đến bảo mật. Việc này giúp họ đưa ra quyết định tốt hơn. Nó giảm thiểu khả năng bị tấn công thành công. Nhận thức không chỉ là về việc tuân thủ quy tắc. Nó còn về việc hiểu được bối cảnh rủi ro. Điều này thúc đẩy một cách tiếp cận chủ động hơn đối với an ninh.

3.3. Hành động dựa trên hành vi và kỳ vọng rõ ràng

Chủ đề thứ ba nhấn mạnh việc công khai các kỳ vọng. Các tổ chức cần thiết lập các quy tắc rõ ràng. Các quy tắc này liên quan đến hành vi bảo mật của nhân viên. Hậu quả cho việc không tuân thủ cần được thông báo trước. Việc khen thưởng các hành vi bảo mật tốt cũng rất quan trọng. Các hành động thích hợp cần được thực hiện. Các hành động này dựa trên hiệu suất an ninh của nhân viên. Điều này tạo ra một môi trường có trách nhiệm giải trình. Nó khuyến khích hành vi mong muốn. Các hình phạt không chỉ là để trừng phạt. Chúng là để củng cố các chính sách bảo mật. Chương trình khen thưởng thúc đẩy sự tham gia tích cực. Nó khuyến khích nhân viên chủ động bảo vệ tổ chức. Việc này biến an ninh mạng thành trách nhiệm chung. Nó không chỉ là gánh nặng của bộ phận CNTT.

IV.Khuyến nghị và tác động đến an ninh dữ liệu

Nghiên cứu đưa ra các khuyến nghị cụ thể. Các khuyến nghị này nhằm cải thiện hiệu quả của chương trình SETA. Mục tiêu cuối cùng là tăng cường an ninh dữ liệu. Các phát hiện cung cấp thông tin thực tiễn cho các nhà lãnh đạo CNTT. Họ có thể phát triển các chương trình mạnh mẽ hơn. Các chương trình này giảm thiểu rủi ro bảo mật trong nhiều ngành. Tác động tiềm năng của nghiên cứu là tạo ra thay đổi xã hội tích cực. Các tổ chức sẽ có khả năng bảo vệ tốt hơn. Họ sẽ bảo vệ hệ thống thông tin và dữ liệu nhạy cảm. Điều này không chỉ giới hạn trong môi trường doanh nghiệp. Các thực hành an ninh mạng tốt hơn cũng sẽ lan rộng. Chúng ảnh hưởng đến cuộc sống cá nhân. Các thành viên gia đình cũng sẽ được bảo vệ tốt hơn.

4.1. Thực hiện SETA thường xuyên và sử dụng phần thưởng

Một khuyến nghị chính là thực hiện SETA thường xuyên. Các hoạt động nhận thức và đào tạo nên diễn ra đều đặn. Chúng cần được duy trì suốt cả năm. Việc này giúp giữ cho thông tin luôn mới mẻ. Nó cũng củng cố các thông điệp bảo mật. Các chương trình SETA cần kết hợp hệ thống phần thưởng. Việc khen thưởng nhân viên cho hành vi bảo mật mong muốn là cần thiết. Nó có thể bao gồm các chương trình công nhận. Hoặc các ưu đãi nhỏ. Đồng thời, cần có các hình phạt thích đáng. Các hình phạt này áp dụng cho các hành vi vi phạm chính sách. Sự kết hợp giữa khuyến khích và răn đe này rất hiệu quả. Nó thúc đẩy văn hóa an ninh tích cực. Nó đảm bảo mọi người đều có trách nhiệm. Nó giúp duy trì một môi trường an toàn. Môi trường này bảo vệ tài sản thông tin.

4.2. Giảm thiểu rủi ro bảo mật trong các ngành

Các phát hiện của nghiên cứu có thể giúp các nhà lãnh đạo CNTT. Họ sẽ phát triển các chương trình SETA hiệu quả. Điều này giảm thiểu rủi ro bảo mật trong nhiều ngành. Thông tin này có thể áp dụng rộng rãi. Không chỉ giới hạn trong ngành khách sạn. Các tổ chức trong lĩnh vực tài chính, y tế, giáo dục đều có thể hưởng lợi. Bất kỳ ngành nào xử lý dữ liệu nhạy cảm cũng vậy. Việc cải thiện SETA góp phần vào thực hành an ninh mạng tốt hơn. Điều này không chỉ ở nơi làm việc. Nó còn ở cả môi trường gia đình. Người dùng mang kiến thức về nhà. Họ áp dụng các thực hành an toàn cho các thiết bị cá nhân. Điều này bảo vệ các thành viên gia đình. Nó nâng cao nhận thức an ninh mạng tổng thể. Kết quả là một xã hội an toàn hơn. Xã hội này được trang bị tốt hơn để đối phó với các mối đe dọa mạng.

Mục lục chi tiết luận án

List of Tables
1. Section 1: Foundation of the Study
1.1. Background of the Problem
1.2. Nature of the Study
1.3. Interview/Survey Questions
1.4. Assumptions, Limitations, and Delimitations
1.5. Significance of the Study
1.5.1. Contribution to Information Technology Practice
1.5.2. Implications for Social Change
1.6. A Review of the Professional and Academic Literature
1.6.1. Social Cognitive Theory
1.6.2. Components and Modes of Human Agency
1.6.3. Triadic Reciprocal Determinism Model and Constructs
1.6.4. Contrasting and Similar Theories
1.6.5. Cybersecurity Awareness and Training
1.6.6. Human Factor in Cybersecurity
1.6.7. Security Education, Training, and Awareness Research
1.7. Transition and Summary
2. Section 2: The Project
2.1. Role of the Researcher
2.2. Research Method and Design
2.3. Population and Sampling
2.4. Data Collection Technique
2.5. Data Organization Techniques
2.6. Data Analysis Technique
2.7. Reliability and Validity
2.8. Transition and Summary
3. Section 3: Application to Professional Practice and Implications for Change
3.1. Overview of Study
3.2. Presentation of the Findings
3.2.1. Theme 1: Consistent, Persistent and Relevant Training and Awareness
3.2.2. Theme 2: Awareness and Training Based Off Threats, Risks and Vulnerabilities
3.2.3. Theme 3: Consequences and Disclosed Expectations
3.3. Applications to Professional Practice
3.4. Implications for Social Change
3.5. Recommendations for Action
3.6. Recommendations for Further Study
3.7. Summary and Study Conclusions
Appendix A: Interview Protocol
Appendix B: Interview Questions
Appendix C: Letter of Invitation
Appendix D: Informed Consent Form
Xem trước tài liệu
Tải đầy đủ để xem toàn bộ nội dung
Exploring cybersecurity awareness and training strategies to prot

Tải xuống file đầy đủ để xem toàn bộ nội dung

Tải đầy đủ (195 trang)

Trích đoạn nội dung luận án

Tải xuống để đọc toàn bộ

Walden University ScholarWorks Walden Dissertations and Doctoral Studies Walden Dissertations and Doctoral Studies Collection 2020 Exploring Cybersecurity Awareness and Training Strategies To Protect Information Systems and Data Michael Hanna Walden University Follow this and additional works at: https://scholarworks.edu/dissertations Part of the Databases and Information Systems Commons, and the Social Psychology Commons This Dissertation is brought to you for free and open access by the Walden Dissertations and Doctoral Studies Collection at ScholarWorks. It has been accepted for inclusion in Walden Dissertations and Doctoral Studies by an authorized administrator of ScholarWorks. For more information, please contact ScholarWorks@waldenu. Walden University College of Management and Technology This is to certify that the doctoral study by Michael Hanna has been found to be complete and satisfactory in all respects, and that any and all revisions required by the review committee have been made.

Review Committee Dr. Bob Duhainy, Committee Chairperson, Information Technology Faculty Dr. Constance Blanson, Committee Member, Information Technology Faculty Dr. Gary Griffith, University Reviewer, Information Technology Faculty Chief Academic Officer and Provost Sue Subocz, Ph.

Walden University 2020 Abstract Exploring Cybersecurity Awareness and Training Strategies To Protect Information Systems and Data by Michael Mohsen Hanna MS, Walden University, 2019 MS, University of Calgary, 2011 BS, University of Calgary, 2005 Doctoral Study Submitted in Partial Fulfillment of the Requirements for the Degree of Doctor of Information Technology Walden University June 2020 Abstract Ineffective security education, training, and awareness (SETA) programs contribute to compromises of organizational information systems and data. Inappropriate actions from users due to ineffective SETA programs may result in legal consequences, fines, reputational damage, adverse impacts on national security, and criminal acts. Grounded in social cognitive theory, the purpose of this qualitative multiple case study was to explore strategies hospitality organizational information technology (IT) leaders utilized to implement SETA successfully. The participants were organizational IT leaders from four organizations in Hampton Roads, Virginia.

Data collection was performed using telephone and video teleconference interviews with organizational IT leaders (n = 6) as well as secondary data analysis of documents related to SETA programs (n = 31). Thematic analysis was used to analyze and code the data, which resulted in three themes. Consistent, persistent, and relevant awareness and training was the first theme to emerge. Awareness and training based on threats, vulnerabilities, and risks was the second theme to emerge.

Disclosing expectations and taking appropriate actions towards employees based on behavior was the third theme to emerge. A recommendation is that SETA should be performed regularly throughout the year while using employee rewards and punishments to promote desired behavior. The findings of this study may promote positive social change by providing information to IT leaders to develop SETA programs and reduce security risks within organizations across various industries. Improved SETA may contribute to improved cyber practices at home and better protect family members.

Exploring Cybersecurity Awareness and Training Strategies To Protect Information Systems and Data by Michael Mohsen Hanna MS, Walden University, 2019 MS, University of Calgary, 2011 BS, University of Calgary, 2005 Doctoral Study Submitted in Partial Fulfillment of the Requirements for the Degree of Doctor of Information Technology Walden University June 2020 Dedication I dedicate this study to my father, Moe, my mother, Nana, and my son, Matthew. First, to my father, who passed away two years before completing this study. He was a PhD in Chemical Engineering and always emphasized the importance of education. He always had an analogy for everything, and many of them related to education.

When I completed my bachelor’s degree, he once joked with me and said he would be impressed when I finished a doctorate degree. I know he was always proud of me, but this accomplishment means so much to me. He taught me the meaning of preserving through the greatest of challenges and the importance of education. I will never forget you, and I will always love you dad.

To my mother, she always taught me the importance of realizing there is more to life than just work and school. She was the other half to my development, and I would not be the man I am today without her. Last, I would like to dedicate this to my one-year-old son. Even though my son cannot read yet, I want him to understand the importance of pushing through the challenges life presents us with.

Matthew, I promise you that I will always be there for you. Acknowledgements I could not have made it to this point of my academic and professional life without my incredible wife, Ryann. My wife and I have gone through the challenges of deployment, building a life together with our son, and completing doctoral programs together. We have both sacrificed so much to get to this point, and I couldn’t have done this without you.

Your love, coaching, and support have meant so much to me from the moment we met. Once again, to my son, Matthew. Just watching you grow up and develop throughout the early stages of your life, you have really shown me what is important in life. I hope the example I try to make and the value I place on education, grit and resiliency are concepts my son takes with him throughout his life.

My ability to persevere came from my parents, and I am so thankful that they have had my back my entire life. I must also thank my doctoral committee for the support and guidance they have provided me. Thank you Dr. Blanson, and Dr.

This has been one of the most significant journeys of my life and it would have not been possible without my doctoral program committee. Table of Contents List of Tables .v Section 1: Foundation of the Study.1 Background of the Problem .2 Nature of the Study .5 Interview/Survey Questions .7 Assumptions, Limitations, and Delimitations. 9 Significance of the Study .10 Contribution to Information Technology Practice. 10 Implications for Social Change.

10 A Review of the Professional and Academic Literature .11 Social Cognitive Theory. 13 Components and Modes of Human Agency. 16 Triadic Reciprocal Determinism Model and Constructs. 20 i Contrasting and Similar Theories.

30 Cybersecurity Awareness and Training. 34 Human Factor in Cybersecurity. 41 Security Education, Training, and Awareness Research. 48 Transition and Summary .49 Section 2: The Project .52 Role of the Researcher .56 Research Method and Design.

63 Population and Sampling. 75 Data Collection Technique. 79 Data Organization Techniques. 81 Data Analysis Technique .83 Reliability and Validity.

90 Transition and Summary .90 Section 3: Application to Professional Practice and Implications for Change .92 Overview of Study .92 Presentation of the Findings.92 Theme 1: Consistent, Persistent and Relevant Training and Awareness. 93 Theme 2: Awareness and Training Based Off Threats, Risks and Vulnerabilities. 99 Theme 3: Consequences and Disclosed Expectations. 105 Applications to Professional Practice .112 Implications for Social Change .116 Recommendations for Action .118 Recommendations for Further Study .122 Summary and Study Conclusions .123 Appendix A: Interview Protocol .174 Appendix B: Interview Questions .177 Appendix C: Letter of Invitation.178 iii Appendix D: Informed Consent Form .180 iv List of Tables Table 1.

Frequency of First Major Theme in Participant Responses and Documentation……………………………………………………………………. Frequency of Second Major Theme in Participant Responses and Documentation……………………………………………………………. Frequency of Third Major Theme in Participant Responses and Documentation……………………………………………………………………108 v 1 Section 1: Foundation of the Study In this section, I will present the background of the problem, problem statement, purpose statement, and nature of the study. I will delineate the assumptions, limitations, and delimitations of the study.

Also, I will present the research question, conceptual framework, and significance of the study. Background of the Problem Organizations utilize a combination of technical and nontechnical security measures to protect information systems and data through a multilayered, defense-in- depth strategy (Conteh & Schmick, 2016). According to Conteh and Schmick (2016), a defense-in-depth strategy consists of security policies, network guidance, audits and compliance, technical solutions, physical security, and security education, training, and awareness (SETA). The weakest layer in an organization’s defense-in-depth strategy is related to the user’s unawareness of cybersecurity best practices, cybersecurity threats, and vulnerabilities (de Bruijn & Janssen, 2017).

The purpose of cybersecurity awareness and training programs are to ultimately protect an organization from the harm posed by cybersecurity vulnerabilities, threats, and attacks by improving employee education, training, and awareness (Beuran et al. The need for better cybersecurity awareness and training strategies are demonstrated by 58% of employees not knowing how to protect an organization from malicious activity, and 98% incorrectly believing security responsibilities are delegated to the system administrators (Hadlington, 2017). Effective SETA strategies are needed to protect users and organizational information systems and data. 2 Problem Statement Humans are the weakest layer in an organization’s cybersecurity program, and their unawareness contributes to an organization’s vulnerabilities (de Bruijn & Janssen, 2017).

The need for better cybersecurity awareness and training strategies are demonstrated by 58% of employees not knowing how to protect an organization from malicious activity, and 98% incorrectly believing security responsibilities are delegated to the system administrators (Hadlington, 2017). The general information technology (IT) problem is that ineffective employee cybersecurity awareness and training programs contribute to compromises of organizational information systems and data. The specific IT problem is that some corporate hospitality IT leaders lack strategies to implement cybersecurity awareness and training programs to protect organizational information systems and data. Purpose Statement The purpose of this qualitative exploratory multiple case study was to explore strategies used by corporate hospitality IT leaders to implement cybersecurity awareness and training programs to protect organizational information systems and data.

The population consisted of corporate hospitality IT leaders including the chief executive officer (CEO), chief operating officer (COO), general managers, chief information officer (CIO), chief information security officer (CISO), and IT directors in Hampton Roads, Virginia, who have implemented cybersecurity awareness and training strategies within their organization. Implications for positive social change include the potential improvement to awareness and training programs that contribute to better cybersecurity 3 practices, which may protect national security, guard critical infrastructure, and prevent disclosure of sensitive information due to compromise that may harm citizens. The improvement of cybersecurity awareness and training also has the potential of protecting these same employees and their families, including children at home, as a result of effective education. The lessons learned at work through awareness and training programs can be retaught at home, which may protect families from crime and nefarious intent.

There is also the potential to contribute new knowledge and insights that may lead to discovery, such as new strategies and tactical level implementations that may protect organizations from damaging events and ultimately improve the cybersecurity culture at a macrolevel. Nature of the Study My intent in this qualitative exploratory multiple case study was to explore organizational cybersecurity awareness and training strategies used to educate employees on practices to protect organizational information systems and data. Multiple case studies enable researchers to acquire a deeper understanding of a phenomenon (Zach, 2006). My intent in this study was to provide depth in understanding the strategies of cybersecurity awareness and training used to educate employees on practices to protect organizational information systems and data.

A qualitative research method was suitable for this study because I focused on multiple organizations and their successful implementation of cybersecurity awareness and training programs. Qualitative research promotes the generation of detailed and rich responses to intricate subjects (Cope, 2014). Therefore, I decided not to collect numerical data to evaluate my research questions, which is 4 explicitly required in a quantitative study. A quantitative study is appropriate when numerical data is used to describe a phenomenon (Carr, 1994).

Mixed methods research encompasses the incorporation of qualitative and quantitative methods and should only be utilized if the combination of methods better explains the research question than a single approach alone (Halcomb, 2019). Because I intended to explore this phenomenon and not describe it with numerical data, quantitative research was not appropriate for this study.

Nội dung được bảo vệ bản quyền — Tải xuống đầy đủ

Trích dẫn luận án này

Michael Mohsen Hanna (2020). Exploring cybersecurity awareness and training strategies to [Luận án tiến sĩ, Walden University]. LuanAn.net. https://luanan.net/cong-nghe-thong-tin/an-toan-thong-tin/exploring-cybersecurity-awareness-and-training-strategies-to-prot

Câu hỏi thường gặp

Luận án "Exploring cybersecurity awareness and training strategies to" nghiên cứu về vấn đề gì?

Khám phá chiến lược nâng cao nhận thức & đào tạo an ninh mạng. Xây dựng môi trường số an toàn.

Luận án "Exploring cybersecurity awareness and training strategies to" được bảo vệ tại trường nào?

Luận án này được bảo vệ tại Walden University. Năm bảo vệ: 2020.

Luận án "Exploring cybersecurity awareness and training strategies to" thuộc chuyên ngành gì?

Luận án "Exploring cybersecurity awareness and training strategies to" thuộc chuyên ngành Information Technology. Danh mục: An Toàn Thông Tin.

Luận án "Exploring cybersecurity awareness and training strategies to" có bao nhiêu trang?

Luận án "Exploring cybersecurity awareness and training strategies to" có 195 trang. Bạn có thể xem trước một phần tài liệu ngay trên trang web trước khi tải về.

Cách tải luận án "Exploring cybersecurity awareness and training strategies to" về máy như thế nào?

Để tải luận án về máy, bạn nhấn nút "Tải xuống ngay" trên trang này, sau đó hoàn tất thanh toán phí lưu trữ. File sẽ được tải xuống ngay sau khi thanh toán thành công. Hỗ trợ qua Zalo: 0559 297 239.

Luận án liên quan

Chia sẻ tài liệu: Facebook Twitter