• DocumentCode
    113449
  • Title

    A conceptual analysis of information security education, information security training and information security awareness definitions

  • Author

    Amankwa, Eric ; Loock, Marianne ; Kritzinger, Elmarie

  • Author_Institution
    Sch. of Comput., Univ. of South Africa, Pretoria, South Africa
  • fYear
    2014
  • fDate
    8-10 Dec. 2014
  • Firstpage
    248
  • Lastpage
    252
  • Abstract
    The importance of information security education, information security training, and information security awareness in organisations cannot be overemphasised. This paper presents working definitions for information security education, information security training and information security awareness. An investigation to determine if any differences exist between information security education, information security training and information security awareness was conducted. This was done to help institutions understand when they need to train or educate employees and when to introduce information security awareness programmes. A conceptual analysis based on the existing literature was used for proposing working definitions, which can be used as a reference point for future information security researchers. Three important attributes (namely focus, purpose and method) were identified as the distinguishing characteristics of information security education, information security training and information security awareness. It was found that these information security concepts are different in terms of their focus, purpose and methods of delivery.
  • Keywords
    industrial training; organisational aspects; security of data; conceptual analysis; delivery method attribute; employee education; employee training; focus attribute; information security awareness; information security education; information security training; purpose attribute; reference point; working definitions; Computers; Educational institutions; Information security; NIST; Training; information security awareness; information security education; information security training;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Internet Technology and Secured Transactions (ICITST), 2014 9th International Conference for
  • Conference_Location
    London
  • Type

    conf

  • DOI
    10.1109/ICITST.2014.7038814
  • Filename
    7038814