A method for implementing an information security awareness campaign within an organisation

dc.contributor.advisorOphoff, Jacobus
dc.contributor.authorScrimgeour, Juan-Marc
dc.date.accessioned2020-05-06T02:48:23Z
dc.date.available2020-05-06T02:48:23Z
dc.date.issued2019
dc.date.updated2020-05-06T01:47:35Z
dc.description.abstractResearch has shown that educating end-users on information security awareness plays an essential part in securing any environment. While best practice standards provide a set of minimum information security awareness controls that should be implemented, little guidance exists on how to implement these controls to ensure the effectiveness of the training. This research set out to define and evaluate a method for implementing an Information Security Awareness Campaign within an organisation based on existing research and standards while assisting the organisation in improving their information security awareness campaign through the creation of artifacts and measurement techniques. A design science research approach guided the research to evaluate changes in the information security awareness campaign implementation method through several research cycles. The method was implemented within an organisation and evaluated based on the impact, effectiveness and results of each step as well as the feedback from participants. The research found both positive and negative results throughout the method. Specific steps within the method proved to be lengthy, time-consuming and confusing to participants. Although many improvements can yet be made, the method was suitable as it achieved the required objective within the organisation. The research outcome provided a risk-based method with a visual representation that demonstrated the lack of awareness of specific information security awareness topics to the organisation. The results of the study not only provided value to the organisation but provided a tried and tested method for implementing an Information Security Awareness Campaign within other organisations.
dc.identifier.apacitationScrimgeour, J. (2019). <i>A method for implementing an information security awareness campaign within an organisation</i>. (). ,Faculty of Commerce ,Department of Information Systems. Retrieved from en_ZA
dc.identifier.chicagocitationScrimgeour, Juan-Marc. <i>"A method for implementing an information security awareness campaign within an organisation."</i> ., ,Faculty of Commerce ,Department of Information Systems, 2019. en_ZA
dc.identifier.citationScrimgeour, J. 2019. A method for implementing an information security awareness campaign within an organisation. . ,Faculty of Commerce ,Department of Information Systems. en_ZA
dc.identifier.ris TY - Thesis / Dissertation AU - Scrimgeour, Juan-Marc AB - Research has shown that educating end-users on information security awareness plays an essential part in securing any environment. While best practice standards provide a set of minimum information security awareness controls that should be implemented, little guidance exists on how to implement these controls to ensure the effectiveness of the training. This research set out to define and evaluate a method for implementing an Information Security Awareness Campaign within an organisation based on existing research and standards while assisting the organisation in improving their information security awareness campaign through the creation of artifacts and measurement techniques. A design science research approach guided the research to evaluate changes in the information security awareness campaign implementation method through several research cycles. The method was implemented within an organisation and evaluated based on the impact, effectiveness and results of each step as well as the feedback from participants. The research found both positive and negative results throughout the method. Specific steps within the method proved to be lengthy, time-consuming and confusing to participants. Although many improvements can yet be made, the method was suitable as it achieved the required objective within the organisation. The research outcome provided a risk-based method with a visual representation that demonstrated the lack of awareness of specific information security awareness topics to the organisation. The results of the study not only provided value to the organisation but provided a tried and tested method for implementing an Information Security Awareness Campaign within other organisations. DA - 2019 DB - OpenUCT DP - University of Cape Town KW - Information Systems LK - https://open.uct.ac.za PY - 2019 T1 - A method for implementing an information security awareness campaign within an organisation TI - A method for implementing an information security awareness campaign within an organisation UR - ER - en_ZA
dc.identifier.urihttps://hdl.handle.net/11427/31786
dc.identifier.vancouvercitationScrimgeour J. A method for implementing an information security awareness campaign within an organisation. []. ,Faculty of Commerce ,Department of Information Systems, 2019 [cited yyyy month dd]. Available from: en_ZA
dc.language.rfc3066eng
dc.publisher.departmentDepartment of Information Systems
dc.publisher.facultyFaculty of Commerce
dc.subjectInformation Systems
dc.titleA method for implementing an information security awareness campaign within an organisation
dc.typeMaster Thesis
dc.type.qualificationlevelMasters
dc.type.qualificationnameMCom
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
thesis_com_2019_scrimgeour_juan_marc.pdf
Size:
2.3 MB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
0 B
Format:
Item-specific license agreed upon to submission
Description:
Collections