2003
DOI: 10.6028/nist.sp.800-50
|View full text |Cite
|
Sign up to set email alerts
|

Building an Information Technology Security Awareness and Training Program

Abstract: NIST) promotes the U.S. economy and public welfare by providing technical leadership for the Nation's measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of concept implementations, and technical analyses to advance the development and productive use of information technology. ITL's responsibilities include the development of technical, physical, administrative, and management standards and guidelines for the cost-effective security and privacy of sensitive unclass… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

3
111
0
6

Year Published

2007
2007
2019
2019

Publication Types

Select...
4
4
1

Relationship

0
9

Authors

Journals

citations
Cited by 150 publications
(120 citation statements)
references
References 0 publications
3
111
0
6
Order By: Relevance
“…On the other hand, Wilson and Harsh defined security education as a process that employees acquire knowledge and technology to perform security activity in preparation for new technologies and threats that might happen [13]. In other words, security education can be defined as an "activity to acquire and practice knowledge on security activities that are required on business in order to prevent and respond to the security incident that are caused by technological change and new threats and intended or unintended behaviors of employees.…”
Section: Security Educationmentioning
confidence: 99%
“…On the other hand, Wilson and Harsh defined security education as a process that employees acquire knowledge and technology to perform security activity in preparation for new technologies and threats that might happen [13]. In other words, security education can be defined as an "activity to acquire and practice knowledge on security activities that are required on business in order to prevent and respond to the security incident that are caused by technological change and new threats and intended or unintended behaviors of employees.…”
Section: Security Educationmentioning
confidence: 99%
“…The National Institute of Standards and Technology (NIST) developed a framework that aims to guide the development of an Information Technology (IT) security programme [24]. This paper identifies the urgent need for an enforced awareness programme to create Internet security awareness among Nigerians.…”
Section: Developing the Awareness Programmementioning
confidence: 99%
“…The effectiveness of these efforts determines the effectiveness of the awareness training program. The successful awareness training program consists of developing ISS policy that reflects the best practices for protecting ISS, informing employees about their responsibilities toward protecting ISS according to the organization procedures and ISS policy, and processes to monitor and review the program (Wilson and Hash, 2003). Hansche (2001) has suggested that the good ISSA program should be designed with taking in account the following points:…”
Section: Information Systems Security (Iss) and The Human Involvementmentioning
confidence: 99%