Top Banner
Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak
22

Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Dec 25, 2015

Download

Documents

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Information Security Awareness Levels of TAFE South Australia Employees

Hong Chan

Bachelor of IT ( Honours )

Supervisor: Dr Sameera Mubarak

Page 2: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Outline Background Information Research Question Methodology Results Conclusion

Page 3: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Information Security Confidentiality – prevent unauthorised access Integrity – accuracy and correctness Availability – authorised access when needed

Ensure business continuity Minimise damage and liability Ethical and legal responsibility

Information security plans or policies are needed, usually consist of technical controls

Background Information

Page 4: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Information Security Awareness – Human Aspects

Employee knowledge of information security concepts

Management knowledge of information security concepts

Consciousness of security plans

Literature suggests positive relationship between awareness and security plan success. Should be included in plans.

Background Information

Page 5: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

TAFE South Australia Largest vocational education provider in SA 2400 employees across over 50 campuses

Suitable for this research All aspects of the business are conducted using

information systems. Holds vast amount of confidential student data. Recently implemented new student

information system

Background Information

Page 6: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Motivation for Research Gap in literature Australian Context Personal interest as an employee

Background Information

Page 7: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Potential Contributions Directly benefit TAFE SA Finalised report (thesis) to be given to TAFE

SA Provide insight into other similar Australian

Organisations

Background Information

Page 8: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

To gain an insight into the information security awareness levels of TAFE SA Employees in order to identify areas that need improvement

Does not look into improving awareness through “best practices”

Research Question

Page 9: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Online Questionnaire Knowledge of concepts = Awareness of threats Behavioural questions = Employee actions which

may cause breaches Consciousness of policies’ existence

Quantitative Methods Used Tabulated percentages

Methodology

Page 10: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Population: 2400 staffSample: 308 responses 13% of entire organisation responded

Demographics Management ( 19% ) General Staff (81%) Mushroom ??

Results

Page 11: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Knew what Phishing is

Knew what Spam is

Results

Yes No

Management 32% 68%

General Employees 23% 77%

Yes No

Management 78% 22%

General Employees 87% 13%

Page 12: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Has clicked on unknown links embedded in external third party emails

Knew what Social Engineering is

Results

Yes No

Management 24% 76%

General Employees 16% 84%

Yes No

Management 78% 22%

General Employees 73% 27%

Page 13: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Knew what a strong password should be

Has given away passwords or logged someone in

Questionnaire may have prompted ICT’s action ??

Results

Yes No

Management 64% 36%

General Employees 66% 34%

Yes No

Management 56% 44%

General Employees 52% 48%

Page 14: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Has left computer unlocked and unattended

Used appropriate methods for password storage

Results

Yes No

Management 73% 27%

General Employees 78% 22%

Yes No

Management 68% 32%

General Employees 65% 35%

Page 15: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Knew the importance of data/information integrity

Has amended data without due process

Results

Yes No

Management 93% 7%

General Employees 91% 9%

Yes No

Management 7% 93%

General Employees 8% 92%

Page 16: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Has discussed work related issues on social networking sites

Very few research into this topic, that is, social media can be a source of data/information leakage

Results

Yes No

Management 7% 93%

General Employees 8% 92%

Page 17: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Awareness of existence of information security policy

Awareness of existence of password policy

Results

Yes No

Management 59% 41%

General Employees 37% 63%

Yes No

Management 41% 59%

General Employees 31% 69%

Page 18: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

TAFE SA needs improvements Passwords given to colleagues Leaving computers unlocked and unattended Lack of awareness of policies

Conclusion

Page 19: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Limitations TAFE SA’s Chief Executive’s disapproval of

question “Social Engineering” is an ambiguous term

Conclusion

Page 20: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Future Research How awareness can be improved Explore adoption of awareness programs Look into Including awareness as part of an

overall security strategy

Conclusion

Page 21: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

My Telstra Story [email protected] Potential for malicious acts is huge!

Page 22: Information Security Awareness Levels of TAFE South Australia Employees Hong Chan Bachelor of IT ( Honours ) Supervisor: Dr Sameera Mubarak.

Thank You

Tip: If you work fulltime, do not commence a research degree.I am actually 19 but I look 40.

-Hong Chan