African Journal of
Business Management

  • Abbreviation: Afr. J. Bus. Manage.
  • Language: English
  • ISSN: 1993-8233
  • DOI: 10.5897/AJBM
  • Start Year: 2007
  • Published Articles: 4194

Full Length Research Paper

Effectiveness of information security awareness methods based on psychological theories

  Bilal Khan1, Khaled S. Alghathbar1, 2, Syed Irfan Nabi1,3 and Muhammad Khurram Khan1*  
Email: [email protected]

  •  Accepted: 24 March 2011
  •  Published: 28 October 2011

Abstract

 

Effective user security awareness campaign can greatly enhance the information assurance posture of an organization. Information security includes organizational aspects, legal aspects, institutionalization and applications of best practices in addition to security technologies. User awareness represents a significant challenge in the security domain, with the human factor ultimately being the element that is exploited in a variety of attack scenarios. Information security awareness program is a critical component in any organizations strategy. In contrast to other information security awareness work which mostly explains methods and techniques for raising information security awareness; this paper discusses and evaluates the effectiveness of different information security awareness tools and techniques on the basis of psychological theories and models. Finally, it describes how to measure information security awareness in an organization.

 

Key words: Information security, awareness, effectiveness, psychological, management.