DocumentCode :
3423289
Title :
Information security competence test with regards to password management
Author :
Tarwireyi, Paul ; Flowerday, Stephen ; Bayaga, A.
Author_Institution :
Dept. of Inf. Syst., Univ. of Fort Hare, East London, South Africa
fYear :
2011
fDate :
15-17 Aug. 2011
Firstpage :
1
Lastpage :
7
Abstract :
It is widely acknowledged that when it comes to IT security the human factor is usually the weakest link. In an effort to strengthen this link, most CIO´s are embracing the deployment of security awareness programmes. It is accepted that these programmes can create an information security-aware culture where security risks can be reduced. Even though work has been done in ensuring that these programmes include mechanisms for changing behaviour and reinforcing good security practices, there is a lack of work on measuring the effectiveness of such programmes. Competence based questions have long been used in HR to select employees with the skills that are necessary to perform effectively in a job. Competence based tests focus mainly on the behaviours and traits critical for success on the job and how they have been demonstrated in the past. This current paper presents the description of an approach that uses competency based behavioural questions to measure security competence levels at a university with regards to password management. A sample of 140 students participated in the study. The findings revealed that even though students were aware of the procedures, many failed to implement them. For example, 48.6% of students would share their passwords even though they know it was wrong. It was also found that there is a positive relationship between the year of study and the creation of strong passwords (n=140; r=+0.268; p=0.007).
Keywords :
educational administrative data processing; educational institutions; security of data; IT security; competency based behavioural question; information security competence test; information technology; password management; security awareness program; security competence level; university; Authentication; Current measurement; Educational institutions; Human factors; Information security; Information Security Awareness; Information Security Behaviour; Password Management;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Security South Africa (ISSA), 2011
Conference_Location :
Johannesburg
Print_ISBN :
978-1-4577-1481-8
Type :
conf
DOI :
10.1109/ISSA.2011.6027524
Filename :
6027524
Link To Document :
بازگشت