Security Education, Training, and Awareness Programs: Literature Review

Siqi Hu,Carol Hsu,Zhongyun Zhou
DOI: https://doi.org/10.1080/08874417.2021.1913671
2021-05-05
Journal of Computer Information Systems
Abstract:Security education, training, and awareness (SETA) is one of the most common and prominent strategies for organizational security governance. However, only a small portion of practitioners claimed that their SETA programs were "very effective". A possible reason for this is the lack of a systematic understanding of the nature of SETA programs, the paths through which SETA impacts employees' security-related beliefs or behavioral intentions, and the conditions that might influence such a relationship. This study argues that a comprehensive literature review regarding SETA is vital for holistically investigating the findings of previous SETA research and unveiling the characteristics and factors that influence the effectiveness of SETA. A total of 80 articles, published between 1998 and 2020, were included to conduct an in-depth systematic review on SETA.
computer science, information systems
What problem does this paper attempt to address?