{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,28]],"date-time":"2026-08-28T06:25:12Z","timestamp":1787898312003,"version":"build-2784847793"},"reference-count":99,"publisher":"Informa UK Limited","issue":"4","funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["71871162"],"award-info":[{"award-number":["71871162"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["71872129"],"award-info":[{"award-number":["71872129"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100013285","name":"Program for Professor of Special Appointment (Eastern Scholar) at Shanghai Institutions of Higher Learning","doi-asserted-by":"crossref","award":["TP2018016"],"award-info":[{"award-number":["TP2018016"]}],"id":[{"id":"10.13039\/501100013285","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["www.tandfonline.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Information Systems"],"published-print":{"date-parts":[[2022,7,4]]},"DOI":"10.1080\/08874417.2021.1913671","type":"journal-article","created":{"date-parts":[[2021,5,6]],"date-time":"2021-05-06T13:12:11Z","timestamp":1620306731000},"page":"752-764","update-policy":"https:\/\/doi.org\/10.1080\/tandf_crossmark_01","source":"Crossref","is-referenced-by-count":49,"title":["Security Education, Training, and Awareness Programs: Literature Review"],"prefix":"10.1080","volume":"62","author":[{"given":"Siqi","family":"Hu","sequence":"first","affiliation":[{"name":"Tongji University","place":["Shanghai, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6545-9467","authenticated-orcid":false,"given":"Carol","family":"Hsu","sequence":"additional","affiliation":[{"name":"Tongji University","place":["Shanghai, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4245-8733","authenticated-orcid":false,"given":"Zhongyun","family":"Zhou","sequence":"additional","affiliation":[{"name":"Tongji University","place":["Shanghai, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"301","published-online":{"date-parts":[[2021,5,5]]},"reference":[{"key":"e_1_3_1_2_1","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2019\/15117"},{"key":"e_1_3_1_3_1","doi-asserted-by":"publisher","DOI":"10.1287\/isre.1070.0160"},{"key":"e_1_3_1_4_1","doi-asserted-by":"publisher","DOI":"10.1108\/09576050210447037"},{"key":"e_1_3_1_5_1","doi-asserted-by":"publisher","DOI":"10.1080\/07421222.2019.1705512"},{"key":"e_1_3_1_6_1","doi-asserted-by":"publisher","DOI":"10.1080\/07421222.2015.1138374"},{"key":"e_1_3_1_7_1","doi-asserted-by":"publisher","DOI":"10.2307\/25750704"},{"key":"e_1_3_1_8_1","unstructured":"Public Law 100\u2013235. Available from: https:\/\/www.govinfo.gov\/content\/pkg\/STATUTE-101\/pdf\/STATUTE-101-Pg1724.pdf#page=1."},{"key":"e_1_3_1_9_1","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-50"},{"key":"e_1_3_1_10_1","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2013\/37.1.01"},{"key":"e_1_3_1_11_1","doi-asserted-by":"publisher","DOI":"10.1108\/09685229810227649"},{"key":"e_1_3_1_12_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.istr.2010.05.002"},{"key":"e_1_3_1_13_1","doi-asserted-by":"publisher","DOI":"10.17705\/1jais.00274"},{"key":"e_1_3_1_14_1","doi-asserted-by":"publisher","DOI":"10.1108\/ICS-10-2014-0065"},{"key":"e_1_3_1_15_1","unstructured":"Resilia A. Cyber Resilience: are your people your most effective defence? AXELOS Limited; 2016."},{"key":"e_1_3_1_16_1","doi-asserted-by":"crossref","first-page":"8","DOI":"10.1016\/S1361-3723(15)30046-4","article-title":"Making security awareness training work","volume":"6","author":"Caldwell T","year":"2016","unstructured":"Caldwell T. Making security awareness training work. Comput. Fraud Secur 2016;6:8\u201314.","journal-title":"Comput. Fraud Secur"},{"key":"e_1_3_1_17_1","volume-title":"Proceedings of 34th International Conference on Information Systems;","author":"Jenkins JL","year":"2013","unstructured":"Jenkins JL, Durcikova A. What, I shouldn\u2019t have done that? The influence of training and just-in-time reminders on secure behavior. Proceedings of 34th International Conference on Information Systems; 2013; Milan, Italy."},{"key":"e_1_3_1_18_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2004.02.005"},{"key":"e_1_3_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/IAW.2006.1652077"},{"key":"e_1_3_1_20_1","doi-asserted-by":"crossref","first-page":"xiii","DOI":"10.2307\/4132319","article-title":"Analyzing the past to prepare for the future: writing a literature review","volume":"26","author":"Webster J","year":"2002","unstructured":"Webster J, Watson RT. Analyzing the past to prepare for the future: writing a literature review. MIS Q 2002;26:xiii\u2013xxiii.","journal-title":"MIS Q"},{"key":"e_1_3_1_21_1","doi-asserted-by":"crossref","unstructured":"Wilson M De Zafra DE Pitcher SI Tressler JD Ippolito JB Information technology security training requirements: a role- and performance-based model. National Institute of Standards and Technology. 1998. Report No: NIST SP.800-16.","DOI":"10.6028\/NIST.SP.800-16"},{"key":"e_1_3_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3130515.3130519"},{"key":"e_1_3_1_23_1","doi-asserted-by":"publisher","DOI":"10.1108\/09685220010371394"},{"key":"e_1_3_1_24_1","volume-title":"Proceedings of the 18th Americas Conference on Information Systems;","author":"Al-Omari A","year":"2012","unstructured":"Al-Omari A, El-Gayar O, Deokar A. Information security policy compliance: the role of information security awareness. Proceedings of the 18th Americas Conference on Information Systems; 2012; Seattle, USA."},{"key":"e_1_3_1_25_1","doi-asserted-by":"publisher","DOI":"10.2307\/25750690"},{"key":"e_1_3_1_26_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijinfomgt.2019.102056"},{"key":"e_1_3_1_27_1","doi-asserted-by":"publisher","DOI":"10.1108\/IMDS-07-2019-0412"},{"key":"e_1_3_1_28_1","doi-asserted-by":"publisher","DOI":"10.1080\/08874417.2016.1153922"},{"key":"e_1_3_1_29_1","first-page":"103","article-title":"Developing an information security awareness program for a Non-Profit organization","volume":"5","author":"Kolb N","year":"2009","unstructured":"Kolb N, Abdullah F. Developing an information security awareness program for a Non-Profit organization. Int. Manage. Rev 2009;5:103\u201308.","journal-title":"Int. Manage. Rev"},{"key":"e_1_3_1_30_1","volume-title":"Proceedings of 34th International Conference on Information Systems;","author":"Haeussinger F","year":"2013","unstructured":"Haeussinger F, Kranz J. Information security awareness: its antecedents and mediating effects on security compliant behavior. Proceedings of 34th International Conference on Information Systems; 2013; Milan, Italy."},{"key":"e_1_3_1_31_1","doi-asserted-by":"crossref","unstructured":"Grance T Nolan T Burke K Dudley R White G Good T Guide to test training and exercise programs for IT plans and capabilities. National Institute of Standards and Technology. 2006. Report No: NIST SP 800-84.","DOI":"10.6028\/NIST.SP.800-84"},{"key":"e_1_3_1_32_1","volume-title":"Proceedings of 27th European Conference on Information Systems;","author":"Alshaikh M","year":"2019","unstructured":"Alshaikh M, Naseer H, Ahmad A, Maynard SB. Toward sustainable behaviour change: an approach for cyber security education training and awareness. Proceedings of 27th European Conference on Information Systems; 2019; Stockhom, Sweden."},{"key":"e_1_3_1_33_1","doi-asserted-by":"publisher","DOI":"10.1111\/deci.12304"},{"key":"e_1_3_1_34_1","doi-asserted-by":"publisher","DOI":"10.17705\/1jais.00595"},{"key":"e_1_3_1_35_1","doi-asserted-by":"publisher","DOI":"10.36965\/OJAKM.2018.6(1)67-80"},{"key":"e_1_3_1_36_1","doi-asserted-by":"publisher","DOI":"10.1057\/s41284-019-00168-8"},{"key":"e_1_3_1_37_1","doi-asserted-by":"publisher","DOI":"10.1111\/isj.12063"},{"key":"e_1_3_1_38_1","volume-title":"Proceedings of 36th International Conference on Information Systems;","author":"Talib YYA","year":"2015","unstructured":"Talib YYA, Dhillon G. Employee ISP compliance intentions: an empirical test of empowerment. Proceedings of 36th International Conference on Information Systems; 2015; Fort Worth, USA."},{"key":"e_1_3_1_39_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2018.02.009"},{"key":"e_1_3_1_40_1","doi-asserted-by":"publisher","DOI":"10.1108\/OIR-11-2015-0358"},{"key":"e_1_3_1_41_1","doi-asserted-by":"publisher","DOI":"10.1108\/ITP-06-2018-0261"},{"key":"e_1_3_1_42_1","volume-title":"Proceedings of 34th Pacific Asia Conference on Information Systems;","author":"Huang H-W","year":"2016","unstructured":"Huang H-W, Parolia N, Cheng K-T. Willingness and ability to perform information security compliance behavior: psychological ownership and self-efficacy perspective. Proceedings of 34th Pacific Asia Conference on Information Systems; 2016; Chiayi, Taiwan."},{"key":"e_1_3_1_43_1","doi-asserted-by":"crossref","unstructured":"AlMindeel R Martins JT Information security awareness in a developing country context: insights from the government sector in Saudi Arabia. ITP. 2020.1\u201319.","DOI":"10.1108\/ITP-06-2019-0269"},{"key":"e_1_3_1_44_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.04.009"},{"key":"e_1_3_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPC.2014.2374011"},{"key":"e_1_3_1_46_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2006.02.008"},{"key":"e_1_3_1_47_1","doi-asserted-by":"publisher","DOI":"10.1057\/ejis.2013.27"},{"key":"e_1_3_1_48_1","doi-asserted-by":"publisher","DOI":"10.19030\/rbis.v15i3.5398"},{"key":"e_1_3_1_49_1","doi-asserted-by":"publisher","DOI":"10.19030\/rbis.v16i4.7435"},{"key":"e_1_3_1_50_1","volume-title":"European Conference on Information Systems","author":"El-Haddadeh R","year":"2012","unstructured":"El-Haddadeh R, Tsohou A, Karyda M. Implementation challenges for information security awareness initiatives in E-government. Proceedings of 20th European Conference on Information Systems; 2012; Barcelona, Spain."},{"key":"e_1_3_1_51_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1353-4858(17)30122-8"},{"key":"e_1_3_1_52_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1386-5056(00)00112-X"},{"key":"e_1_3_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICITST.2014.7038814"},{"key":"e_1_3_1_54_1","doi-asserted-by":"publisher","DOI":"10.1201\/1086\/45241.14.2.20050501\/88292.6"},{"key":"e_1_3_1_55_1","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-171r2"},{"key":"e_1_3_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/1027802.1027882"},{"key":"e_1_3_1_57_1","doi-asserted-by":"publisher","DOI":"10.1108\/09685229510792988"},{"key":"e_1_3_1_58_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2015.04.006"},{"key":"e_1_3_1_59_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1353-4858(06)70337-3"},{"key":"e_1_3_1_60_1","doi-asserted-by":"publisher","DOI":"10.7603\/s40601-013-0019-8"},{"key":"e_1_3_1_61_1","doi-asserted-by":"publisher","DOI":"10.1201\/1086\/43298.9.6.20010102\/30985.4"},{"key":"e_1_3_1_62_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1353-4858(08)70109-0"},{"key":"e_1_3_1_63_1","volume-title":"Proceedings of 14th Americas Conference on Information Systems;","author":"Heikka J.","year":"2008","unstructured":"Heikka J. A constructive approach to information systems security training: an action research experience. Proceedings of 14th Americas Conference on Information Systems; 2008; Toronto, Canada."},{"key":"e_1_3_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2013.106"},{"key":"e_1_3_1_65_1","doi-asserted-by":"publisher","DOI":"10.1080\/0144929X.2012.708787"},{"key":"e_1_3_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/1281320.1281322"},{"key":"e_1_3_1_67_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101827"},{"key":"e_1_3_1_68_1","doi-asserted-by":"publisher","DOI":"10.1049\/iet-sen.2018.5095"},{"key":"e_1_3_1_69_1","doi-asserted-by":"publisher","DOI":"10.4018\/joeuc.2013070104"},{"key":"e_1_3_1_70_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.compedu.2008.06.011"},{"key":"e_1_3_1_71_1","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2012.285"},{"key":"e_1_3_1_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2006.110"},{"key":"e_1_3_1_73_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2006.10.009"},{"key":"e_1_3_1_74_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.compedu.2013.10.013"},{"key":"e_1_3_1_75_1","doi-asserted-by":"publisher","DOI":"10.1080\/15536548.2013.10845672"},{"key":"e_1_3_1_76_1","doi-asserted-by":"publisher","DOI":"10.1108\/09685220810920558"},{"key":"e_1_3_1_77_1","doi-asserted-by":"publisher","DOI":"10.1080\/19393550802492487"},{"key":"e_1_3_1_78_1","unstructured":"Dugan N Security awareness training in a corporate setting [Doctoral Dissertation] IOWA STATE UNIVERSITY. 2018."},{"key":"e_1_3_1_79_1","doi-asserted-by":"publisher","DOI":"10.1201\/1086\/43316.10.3.20010701\/31727.6"},{"key":"e_1_3_1_80_1","doi-asserted-by":"publisher","DOI":"10.1108\/09685221211219182"},{"key":"e_1_3_1_81_1","doi-asserted-by":"publisher","DOI":"10.17705\/1jais.00506"},{"key":"e_1_3_1_82_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2009.12.005"},{"key":"e_1_3_1_83_1","unstructured":"Adepeju-Joseph S. The ELM as behavior modeling technique for effective cybersecurity training awareness and education development [Doctoral Dissertation]. University of Nebraska. 2018."},{"key":"e_1_3_1_84_1","doi-asserted-by":"publisher","DOI":"10.1080\/15332861.2010.487415"},{"key":"e_1_3_1_85_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSA.2011.6027505"},{"key":"e_1_3_1_86_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101640"},{"key":"e_1_3_1_87_1","doi-asserted-by":"publisher","DOI":"10.1108\/09685220810908787"},{"key":"e_1_3_1_88_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.03.003"},{"key":"e_1_3_1_89_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.chb.2016.11.065"},{"key":"e_1_3_1_90_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.heliyon.2019.e02010"},{"key":"e_1_3_1_91_1","volume-title":"Proceedings of 22nd Americas Conference on Information Systems;","author":"Abed J","year":"2016","unstructured":"Abed J, Dhillon G, Ozkan S. Investigating continuous security compliance behavior: insights from information systems continuance model. Proceedings of 22nd Americas Conference on Information Systems; 2016; San Diego, USA."},{"key":"e_1_3_1_92_1","unstructured":"Brady JW An investigation of factors that affect HIPAA security compliance in academic medical centers [Doctoral dissertation]. Nova Southeastern University. 2010."},{"key":"e_1_3_1_93_1","volume-title":"Proceedings of 31st International Conference on Information Systems;","author":"Jenkins JL","year":"2010","unstructured":"Jenkins JL, Durcikova A, Ross G, Nunamaker JF. Encouraging users to behave securely: examining the influence of technical, managerial, and educational controls on Users\u2019 secure behavior. Proceedings of 31st International Conference on Information Systems; 2010; St. Louis, USA."},{"key":"e_1_3_1_94_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10551-008-9909-7"},{"key":"e_1_3_1_95_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101594"},{"key":"e_1_3_1_96_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.pmcj.2016.06.007"},{"key":"e_1_3_1_97_1","doi-asserted-by":"publisher","DOI":"10.1108\/ITP-10-2017-0322"},{"key":"e_1_3_1_98_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2016.12.016"},{"key":"e_1_3_1_99_1","doi-asserted-by":"publisher","DOI":"10.4018\/JGIM.2019040106"},{"key":"e_1_3_1_100_1","volume-title":"Curriculum Perspectives and Practice","author":"Miller JP","year":"1985","unstructured":"Miller JP, Seller W. Curriculum Perspectives and Practice. Longman Inc. (95 Church Street, White Plains, NY 10601): Pearson Education Canada; 1985."}],"container-title":["Journal of Computer Information Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.tandfonline.com\/doi\/pdf\/10.1080\/08874417.2021.1913671","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,5]],"date-time":"2026-03-05T09:30:26Z","timestamp":1772703026000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.tandfonline.com\/doi\/full\/10.1080\/08874417.2021.1913671"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,5,5]]},"references-count":99,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2022,7,4]]}},"alternative-id":["10.1080\/08874417.2021.1913671"],"URL":"https:\/\/doi.org\/10.1080\/08874417.2021.1913671","relation":{},"ISSN":["0887-4417","2380-2057"],"issn-type":[{"value":"0887-4417","type":"print"},{"value":"2380-2057","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,5,5]]},"assertion":[{"value":"The publishing and review policy for this title is described in its Aims & Scope.","order":1,"name":"peerreview_statement","label":"Peer Review Statement"},{"value":"http:\/\/www.tandfonline.com\/action\/journalInformation?show=aimsScope&journalCode=ucis20","URL":"http:\/\/www.tandfonline.com\/action\/journalInformation?show=aimsScope&journalCode=ucis20","order":2,"name":"aims_and_scope_url","label":"Aim & Scope"},{"value":"2021-05-05","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}