4.5 Review

Enhancing employees information security awareness in private and public organisations: A systematic literature review

Journal

COMPUTERS & SECURITY
Volume 106, Issue -, Pages -

Publisher

ELSEVIER ADVANCED TECHNOLOGY
DOI: 10.1016/j.cose.2021.102267

Keywords

Information security awareness; Literature review; Private organisations; Public organisations; Information Security Management; Awareness methods; Awareness factors

Ask authors/readers for more resources

Preserving the confidentiality, integrity, and availability of an organization's sensitive information systems assets against attacks and threats is a challenge in the digital age. The study highlights the importance of employee information security awareness in preventing undesirable behaviors, and offers insights into methods and factors used to enhance ISA in private and public organizations. The results show that various methods and factors are employed to enhance employees' ISA, with theoretical models and gamification being widely used across sectors.
Preserving the confidentiality, integrity and availability (CIA) of an organisation's sensitive information systems assets against attacks and threats is a challenge in this digital age. Or-ganisations worldwide make huge investments in information security technological coun-termeasures. Nonetheless, organisations in many cases fail to protect their information as-sets as they rely mainly on technical solutions which are not contextually compatible and sufficient. As a matter of fact, a significant number of organisational information security in-cidents are due to the exploitation of human elements that directly and/or indirectly cause the majority of security incidents. Therefore, employees' information security awareness (ISA) becomes one of the critical aspects of protection against undesirable information se-curity behaviours. However, to date, there is limited synthesised knowledge about methods for enhancing ISA and integrated insights on factors affecting employees' ISA levels. This study, therefore, provides a systematic review of the literature on ISA and puts forward a state-of-the-art collection of ISA methods and factors for enhancing employees' ISA within both private and public sector organisations. The results indicate that various methods and factors are used to enhance employees' ISA in organisations. Theoretical models and gami-fication are the methods widely used in both private and public organisations, whereas the constructivist approach and violation detections are some of the methods used only in pri-vate organisations. Furthermore, this study offers some insights into the latest trends in ISA content development methods and factors, and fosters good ISA practice by disseminating information and knowledge amongst Information Security professionals to help them build an overarching ISA development programme in their organisations. (c) 2021 The Author(s). Published by Elsevier Ltd. This is an open access article under the CC BY license ( http://creativecommons.org/licenses/by/4.0/ )

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.5
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available