{"title":"A Design Theory-Based Gamification Approach for Information Security Training","authors":"T. Nguyen, H. Pham","doi":"10.1109/RIVF48685.2020.9140730","DOIUrl":null,"url":null,"abstract":"This study reviews previous information security (InfoSec) training studies and identifies three significant gaps. They are (1) lacking pedagogical theories developed specifically in IS training context, therefore, lacking appropriate pedagogical theory-based training approaches; (2) ineffectiveness of InfoSec training delivery methods due to unengaging, non-authentic security risks and training activities; and (3) and lacking an effective way of measuring effectiveness of InfoSec training. The paper proposes employing design theory as the theoretical basis for InfoSec training, and gamification as the main training and testing method to overcome these gaps. We argue that the design theory for InfoSec training associated with gamification can improve learning results for training and effectiveness testing through providing a joyful, realistic and interactive training. An action research is proposed to further evaluate the effectiveness of the approach.","PeriodicalId":169999,"journal":{"name":"2020 RIVF International Conference on Computing and Communication Technologies (RIVF)","volume":"16 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 RIVF International Conference on Computing and Communication Technologies (RIVF)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/RIVF48685.2020.9140730","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
This study reviews previous information security (InfoSec) training studies and identifies three significant gaps. They are (1) lacking pedagogical theories developed specifically in IS training context, therefore, lacking appropriate pedagogical theory-based training approaches; (2) ineffectiveness of InfoSec training delivery methods due to unengaging, non-authentic security risks and training activities; and (3) and lacking an effective way of measuring effectiveness of InfoSec training. The paper proposes employing design theory as the theoretical basis for InfoSec training, and gamification as the main training and testing method to overcome these gaps. We argue that the design theory for InfoSec training associated with gamification can improve learning results for training and effectiveness testing through providing a joyful, realistic and interactive training. An action research is proposed to further evaluate the effectiveness of the approach.