{"id":{"repo_id":"emich","oai_identifier":"oai:commons.emich.edu:theses-2059"},"canonical_url":"https://search.dev.ndltd.org/etd/emich/oai:commons.emich.edu:theses-2059","repository":{"repo_id":"emich","name":"Eastern Michigan University","base_url":"https://commons.emich.edu/do/oai/"},"display":{"title":"A study of information security awareness program effectiveness in predicting end-user security behavior","abstract":"<p>As accessibility to data increases, so does the need to increase security. For organizations of all sizes, information security (IS) has become paramount due to the increased use of the Internet. Corporate data are transmitted ubiquitously over wireless networks and have increased exponentially with cloud computing and growing end-user demand. Both technological and human strategies must be employed in the development of an information security awareness (ISA) program. By creating a positive culture that promotes desired security behavior through appropriate technology, security policies, and an understanding of human motivations, ISA programs have been the norm for organizational end-user risk mitigation for a number of years (Peltier, 2013; Tsohou, Karyda, Kokolakis, & Kiountouzis, 2015; Vroom & Solms, 2004). By studying the human factors that increase security risks, more effective security frameworks can be implemented. This study focused on testing the effectiveness of ISA programs on enduser security behavior.</p> <p>The study included the responses of 99/400 employees at a mid-size corporation. The theory of planned behavior was used as model to measure the results of the tool. Unfortunately, while data collected indicated that ISA does cause change in security behavior, the data also showed no significance. Thus, we fail to reject the null hypothesis.</p>","abstract_html":"&lt;p&gt;As accessibility to data increases, so does the need to increase security. For organizations of all sizes, information security (IS) has become paramount due to the increased use of the Internet. Corporate data are transmitted ubiquitously over wireless networks and have increased exponentially with cloud computing and growing end-user demand. Both technological and human strategies must be employed in the development of an information security awareness (ISA) program. By creating a positive culture that promotes desired security behavior through appropriate technology, security policies, and an understanding of human motivations, ISA programs have been the norm for organizational end-user risk mitigation for a number of years (Peltier, 2013; Tsohou, Karyda, Kokolakis, &amp; Kiountouzis, 2015; Vroom &amp; Solms, 2004). By studying the human factors that increase security risks, more effective security frameworks can be implemented. This study focused on testing the effectiveness of ISA programs on enduser security behavior.&lt;/p&gt; &lt;p&gt;The study included the responses of 99/400 employees at a mid-size corporation. The theory of planned behavior was used as model to measure the results of the tool. Unfortunately, while data collected indicated that ISA does cause change in security behavior, the data also showed no significance. Thus, we fail to reject the null hypothesis.&lt;/p&gt;","abstract_has_math":false,"creators":["Banfield, James Michael"],"institution":null,"degree_name":"Doctor of Philosophy (PhD)","degree_level":"Open Access Dissertation","degree_discipline":"College of Technology","degree_department":null,"school":null,"contributors":["Denise Pilato, Ph.D.","Bilquis Ferdousi, Ph.D.","Michael McVey, Ed.D"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2016,"date_issued":"2016-08-31T07:00:00Z","date_published":"2016-08-31T07:00:00Z","updated_at":"2026-07-24T02:17:06Z","subjects":["Information Awareness","Information Policy","Information Security","Security Behavior","Science and Technology Studies","Technology and Innovation"],"languages":[],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://commons.emich.edu/theses/692","outbound_label":"Repository record","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Denise Pilato, Ph.D.","Bilquis Ferdousi, Ph.D.","Michael McVey, Ed.D"]},{"key":"dc:creator","label":"Author","values":["Banfield, James Michael"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.available","label":"Dc Date Available","values":["2017-05-30T07:00:00Z"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["College of Technology"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Open Access Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Doctor of Philosophy (PhD)"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Information Awareness","Information Policy","Information Security","Security Behavior","Science and Technology Studies","Technology and Innovation"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://commons.emich.edu/theses/692"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["<p>As accessibility to data increases, so does the need to increase security. For organizations of all sizes, information security (IS) has become paramount due to the increased use of the Internet. Corporate data are transmitted ubiquitously over wireless networks and have increased exponentially with cloud computing and growing end-user demand. Both technological and human strategies must be employed in the development of an information security awareness (ISA) program. By creating a positive culture that promotes desired security behavior through appropriate technology, security policies, and an understanding of human motivations, ISA programs have been the norm for organizational end-user risk mitigation for a number of years (Peltier, 2013; Tsohou, Karyda, Kokolakis, & Kiountouzis, 2015; Vroom & Solms, 2004). By studying the human factors that increase security risks, more effective security frameworks can be implemented. This study focused on testing the effectiveness of ISA programs on enduser security behavior.</p> <p>The study included the responses of 99/400 employees at a mid-size corporation. The theory of planned behavior was used as model to measure the results of the tool. Unfortunately, while data collected indicated that ISA does cause change in security behavior, the data also showed no significance. Thus, we fail to reject the null hypothesis.</p>"]},{"key":"dc:title","label":"Title","values":["A study of information security awareness program effectiveness in predicting end-user security behavior"]}]}],"canonical_facts":{"dc:contributor":["Denise Pilato, Ph.D.","Bilquis Ferdousi, Ph.D.","Michael McVey, Ed.D"],"dc:creator":["Banfield, James Michael"],"dc:date.available":["2017-05-30T07:00:00Z"],"dc:description.abstract":["<p>As accessibility to data increases, so does the need to increase security. For organizations of all sizes, information security (IS) has become paramount due to the increased use of the Internet. Corporate data are transmitted ubiquitously over wireless networks and have increased exponentially with cloud computing and growing end-user demand. Both technological and human strategies must be employed in the development of an information security awareness (ISA) program. By creating a positive culture that promotes desired security behavior through appropriate technology, security policies, and an understanding of human motivations, ISA programs have been the norm for organizational end-user risk mitigation for a number of years (Peltier, 2013; Tsohou, Karyda, Kokolakis, & Kiountouzis, 2015; Vroom & Solms, 2004). By studying the human factors that increase security risks, more effective security frameworks can be implemented. This study focused on testing the effectiveness of ISA programs on enduser security behavior.</p> <p>The study included the responses of 99/400 employees at a mid-size corporation. The theory of planned behavior was used as model to measure the results of the tool. Unfortunately, while data collected indicated that ISA does cause change in security behavior, the data also showed no significance. Thus, we fail to reject the null hypothesis.</p>"],"dc:identifier":["https://commons.emich.edu/theses/692"],"dc:subject":["Information Awareness","Information Policy","Information Security","Security Behavior","Science and Technology Studies","Technology and Innovation"],"dc:title":["A study of information security awareness program effectiveness in predicting end-user security behavior"],"thesis:degree_discipline":["College of Technology"],"thesis:degree_level":["Open Access Dissertation"],"thesis:degree_name":["Doctor of Philosophy (PhD)"]},"updated_at":"2026-07-24T02:17:06Z"}