Using Design-Science Based Gamification to Improve Organizational Security Training and Compliance

成果类型:
Article
署名作者:
Silic, Mario; Lowry, Paul Benjamin
署名单位:
University of St Gallen; Virginia Polytechnic Institute & State University
刊物名称:
JOURNAL OF MANAGEMENT INFORMATION SYSTEMS
ISSN/ISSBN:
0742-1222
DOI:
10.1080/07421222.2019.1705512
发表日期:
2020
页码:
129-161
关键词:
information-systems Intrinsic motivation policy compliance self-efficacy user TECHNOLOGY IMPACT MODEL deterrence FRAMEWORK
摘要:
We conducted a design-science research project to improve an organization's compound problems of (1) unsuccessful employee phishing prevention and (2) poorly received internal security training. To do so, we created a gamified security training system focusing on two factors: (1) enhancing intrinsic motivation through gamification and (2) improving security learning and efficacy. Our key theoretical contribution is proposing a recontextualized kernel theory from the hedonic-motivation system adoption model that can be used to assess employee security constructs along with their intrinsic motivations and coping for learning and compliance. A six-month field study with 420 participants shows that fulfilling users' motivations and coping needs through gamified security training can result in statistically significant positive behavioral changes. We also provide a novel empirical demonstration of the conceptual importance of appropriate challenge in this context. We vet our work using the principles of proof-of-concept and proof-of-value, and we conclude with a research agenda that leads toward final proof-in-use.