Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • harvard-cite-them-right
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Utbildningens roll i IT-säkerhet: En kvalitativ studie om medvetenhetens påverkan på efterlevnad av IT-säkerhetspolicy.
University of Borås, Faculty of Librarianship, Information, Education and IT.
University of Borås, Faculty of Librarianship, Information, Education and IT.
2024 (Swedish)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesisAlternative title
The role of education in IT security : A qualitative study on the impact of awareness on IT security policy compliance. (English)
Abstract [sv]

Syftet med denna studie var att undersöka och förstå hur utbildning av medarbetare och IT-säkerhetsmedvetenhet påverkar deras efterlevnad av IT-säkerhetspolicy, samt att utforska vilken typ av utbildning som anses vara mest effektiv. För att uppnå detta användes ett antal tillvägagångssätt, såsom semi-strukturerade intervjuer, där respondenternas svar kategoriserades med öppen och axial kodning. En dokumentundersökning genomfördes också för att jämföra den insamlade datan med tidigare forskning inom området. Resultaten av studien ledde till utvecklingen av en modell (Figur 5) som beskriver sambandet mellan utbildning, medvetenhet, sociala sammanhang och IT-säkerhet. Studien visar att utbildning har en betydande inverkan på IT-säkerhet, men för att den ska vara effektiv måste medarbetarna ha en hög nivå av medvetenhet om IT-säkerhetsfrågor. Dessutom framkom det att en kombination av teoretisk och praktisk utbildning, tillsammans med kontinuerliga insatser för att öka medvetenheten, är nödvändig för att förstärka IT-säkerhetskulturen inom organisationer. Slutsatserna från denna studie bidrar till en djupare förståelse av hur utbildning och medvetenhet kan integreras för att förbättra IT-säkerheten i arbetsmiljöer. Figur 5 kan fungera som en guide för organisationer som strävar efter att förbättra sin IT-säkerhet genom riktade utbildningsinsatser och medvetenhetsskapande åtgärder. Detta är särskilt iktigt i dagens digitala samhälle där IT-säkerhet har blivit en kritisk faktor för organisatorisk framgång och skydd av känslig information. 

Abstract [en]

The purpose of this study was to investigate how employee training and IT security awareness influence their adherence to IT security practices, as well as to explore which type of training is considered most effective. To achieve this, a number of approaches were used, such as semistructured interviews, where respondents' answers were categorized using open and axial coding. A document analysis was also conducted to compare the collected data with previous research in the field. The results of the study led to the development of a model describing the relationship between training, awareness, social contexts, and IT security. The study shows that training has a significant impact on IT security, but for it to be effective, employees must have a high level of awareness regarding IT security issues. Furthermore, it was found that a combination of theoretical and practical training, along with continuous efforts to increase awareness, is necessary to strengthen the IT security culture within organizations. The conclusions from this study contribute to a deeper understanding of how training and awareness can be integrated to improve IT security in work environments. The presented model can serve as a guide for organizations striving to enhance their IT security through targeted training initiatives and awareness-raising measures. This is particularly important in today's digital society, where IT security has become a critical factor for organizational success and the protection of sensitive information.

Place, publisher, year, edition, pages
2024.
Keywords [en]
Cybersecurity, IT-security, IT-security policys, IT-security awareness, user behavior, user education
Keywords [sv]
Användarbeteende, utbildning, cybersäkerhet, IT-säkerhetspolicy, IT-säkerhet, IT-säkerhetsmedvetande
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:hb:diva-32857OAI: oai:DiVA.org:hb-32857DiVA, id: diva2:1916516
Subject / course
Informatics
Available from: 2024-12-06 Created: 2024-11-27 Last updated: 2025-09-24Bibliographically approved

Open Access in DiVA

2024KANI19(947 kB)134 downloads
File information
File name FULLTEXT01.pdfFile size 947 kBChecksum SHA-512
4c01de33a4630486e45786238ab7edbc130e89b5b6febdace3d148483f8a56434095016ccc5fe3d5009b5abcf0802a922076bfc1094b9f746749058eea6d7f26
Type fulltextMimetype application/pdf

By organisation
Faculty of Librarianship, Information, Education and IT
Computer and Information Sciences

Search outside of DiVA

GoogleGoogle Scholar
Total: 134 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 170 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • harvard-cite-them-right
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf