{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:31:44Z","timestamp":1781105504414,"version":"3.54.1"},"reference-count":53,"publisher":"IGI Global Scientific Publishing","issue":"4","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013,10,1]]},"abstract":"<p>Identification and access management (I\/AM) is among the top security issues facing institutions of higher education. Most institutions of higher education require end users to provide usernames and passwords to gain access to personally identifiable information (PII). This leaves universities vulnerable to unauthorized access and unauthorized disclosure of PII as, according to recent literature, usernames and passwords alone are insufficient for proper authentication of users into information and information systems. This study examines a critical element in the successful implementation of any information security initiative, end user training. Specifically, this study advances research in the area of end user security training by using canonical action research (CAR) to develop and refine an IT security training framework that can guide institutions of higher education in the implementation of USB security tokens for two-factor authentication using public key infrastructure (PKI).<\/p>","DOI":"10.4018\/joeuc.2013100104","type":"journal-article","created":{"date-parts":[[2014,1,23]],"date-time":"2014-01-23T11:13:07Z","timestamp":1390475587000},"page":"75-103","source":"Crossref","is-referenced-by-count":3,"title":["End User Security Training for Identification and Access Management"],"prefix":"10.4018","volume":"25","author":[{"given":"Tonia","family":"San Nicolas-Rocca","sequence":"first","affiliation":[{"name":"School of Library and Information Science, San Jose State University, San Jose, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lorne","family":"Olfman","sequence":"additional","affiliation":[{"name":"Center for Information Systems and Technology, Claremont Graduate University, Claremont, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"joeuc.2013100104-0","doi-asserted-by":"crossref","unstructured":"Ahituv, N. (1989, December 4-6). Assessing the value of information: Problems and approaches. In Proceedings of the Tenth International Conference on Information Systems, Boston, MA.","DOI":"10.1145\/75034.75061"},{"key":"joeuc.2013100104-1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2006.11.004"},{"key":"joeuc.2013100104-2","first-page":"14","article-title":"Current issues survey report.","volume":"2","author":"D. H.Allison","year":"2008","journal-title":"EDUCAUSE Quarterly"},{"key":"joeuc.2013100104-3","unstructured":"Athanasopoulos, V. (2004). Design and development of a web-based DOD PKI common access card (CAC) instruction tool. Master's thesis, Naval Postgraduate School."},{"key":"joeuc.2013100104-4","doi-asserted-by":"publisher","DOI":"10.1287\/orsc.3.1.1"},{"key":"joeuc.2013100104-5","doi-asserted-by":"publisher","DOI":"10.1177\/017084069201300104"},{"key":"joeuc.2013100104-6","doi-asserted-by":"publisher","DOI":"10.1145\/63238.63241"},{"issue":"3","key":"joeuc.2013100104-7","doi-asserted-by":"crossref","first-page":"329","DOI":"10.2307\/25148642","article-title":"Special issue on action research in information systems: Making IS research relevant to practice\u2013foreward.","volume":"28","author":"R.Baskerville","year":"2004","journal-title":"Management Information Systems Quarterly"},{"key":"joeuc.2013100104-8","doi-asserted-by":"publisher","DOI":"10.2307\/249565"},{"key":"joeuc.2013100104-9","doi-asserted-by":"publisher","DOI":"10.1080\/026839696345289"},{"key":"joeuc.2013100104-10","doi-asserted-by":"publisher","DOI":"10.1057\/palgrave.ejis.3000298"},{"key":"joeuc.2013100104-11","doi-asserted-by":"publisher","DOI":"10.1002\/jcaf.20412"},{"key":"joeuc.2013100104-12","doi-asserted-by":"publisher","DOI":"10.2307\/249313"},{"issue":"2","key":"joeuc.2013100104-13","first-page":"12","article-title":"Current issues survey report.","volume":"30","author":"J. S.Camp","year":"2007","journal-title":"EDUCAUSE Quarterly"},{"key":"joeuc.2013100104-14","unstructured":"Charoen, D. (2006). End users' behaviors in utilizations of passwords: An action research approach. Unpublished doctoral dissertation, Claremont Graduate University."},{"key":"joeuc.2013100104-15","unstructured":"Clark, R. (2009). A sufficiently rich model of (id)entity, authentication and authorization. The 2nd Multidisciplinary Workshop on Identity in the Information Society, LSE."},{"key":"joeuc.2013100104-16","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2006.10.005"},{"key":"joeuc.2013100104-17","doi-asserted-by":"publisher","DOI":"10.4018\/joeuc.2010070102"},{"key":"joeuc.2013100104-18","unstructured":"Coulson, T., Zhu, J. Miyuan, S., & Rohm, C. E. T. (2006). The price of security: The challenge of measuring business value investments in securing information systems. Communications of the International Information Management Association, 5(4)."},{"key":"joeuc.2013100104-19","unstructured":"CSI\/FBI. (2007). CSI survey 2007: The 12th annual computer crime and security survey. Computer Security Institute. Retrieved January 8, 2008, from http:\/\/i.cmpnet.com\/v2.gocsi.com\/pdf\/CSISurvey2007.pdf"},{"key":"joeuc.2013100104-20","doi-asserted-by":"publisher","DOI":"10.2307\/249008"},{"key":"joeuc.2013100104-21","doi-asserted-by":"publisher","DOI":"10.1111\/j.1365-2575.2004.00162.x"},{"issue":"11","key":"joeuc.2013100104-22","first-page":"42","article-title":"How strong are your passwords?","volume":"89","author":"D.Fordham","year":"2008","journal-title":"Strategic Finance"},{"key":"joeuc.2013100104-23","doi-asserted-by":"publisher","DOI":"10.1177\/001872677202500605"},{"issue":"6","key":"joeuc.2013100104-24","doi-asserted-by":"crossref","first-page":"337","DOI":"10.17705\/1jais.00040","article-title":"Change as crisis or growth? Toward a trans-disciplinary view of information systems as a field of study - a response to Benbasat and Zmud's call for returning to the IT artifact.","volume":"4","author":"R.Galliers","year":"2003","journal-title":"Journal of the Association for Information Systems"},{"key":"joeuc.2013100104-25","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2004.41"},{"key":"joeuc.2013100104-26","doi-asserted-by":"publisher","DOI":"10.1016\/j.jengtecman.2012.03.007"},{"key":"joeuc.2013100104-27","author":"S.Harris","year":"2012","journal-title":"CISSP all in one exam guide"},{"key":"joeuc.2013100104-28","unstructured":"Hawkins, B. (2007). What higher Ed leaders need to know about IdM. EDUCAUSE Review, 42(5), 84-85. Retrieved April 6, 2008, from http:\/\/www.educause.edu\/er\/erm07\/erm07510.asp"},{"key":"joeuc.2013100104-29","doi-asserted-by":"publisher","DOI":"10.1111\/j.1467-6486.1980.tb00087.x"},{"key":"joeuc.2013100104-30","unstructured":"Ingerman, B., & Yang, C., & the EDUCAUSE Current Issues Committee. (2010). Top ten IT issues, 2010. EDUCAUSE Review, 45(3), 46-60. Retrieved January 13, 2011, from http:\/\/www.educause.edu\/EDUCAUSE+Review\/TopTenITIssues2010\/205503"},{"issue":"3","key":"joeuc.2013100104-31","doi-asserted-by":"crossref","first-page":"549","DOI":"10.2307\/25750691","article-title":"Fear appeals and information security behaviors: An empirical study.","volume":"34","author":"A.Johnson","year":"2010","journal-title":"Management Information Systems Quarterly"},{"key":"joeuc.2013100104-32","first-page":"27","article-title":"Relevance and rigor in information systems research: Improving quality confidence cohesion and impact","author":"P.Keen","year":"1991","journal-title":"Information systems research: Contemporary approaches and emergent traditions"},{"key":"joeuc.2013100104-33","unstructured":"Linden, M., Linna, P., Kivilompolo, M., & Kanner, J. (2002). Lessons learned in PKI implementation in higher education. In Proceedings of the 8th International Conference of European University Information Systems (pp. 19-22)."},{"key":"joeuc.2013100104-34","doi-asserted-by":"crossref","unstructured":"Lindgren, R., Henfridsson, O., & Schultze, U. (2004). Design principles for competence management systems: A synthesis of an action research study. MIS Quarterly, 28(3), Special Issue on Action Research in Information Systems, 435-472.","DOI":"10.2307\/25148646"},{"key":"joeuc.2013100104-35","doi-asserted-by":"publisher","DOI":"10.4156\/ijact.vol2.issue4.1"},{"key":"joeuc.2013100104-36","unstructured":"NIST SP 800-16 (1998). Information technology training requirements: A role- and performance-based model (NIST Special Publication 800-16). Washington, DC: US Department of Commerce."},{"key":"joeuc.2013100104-37","unstructured":"Olfman, L., Bostrom, R., & Sein, M. (2006). Developing training strategies with an HCI perspective. In Galletta, D. & Zhang P. (Eds.), Human-Computer Interaction and Management Information Systems, 2(10), 258-283. M. E. Sharpe, Inc."},{"issue":"4","key":"joeuc.2013100104-38","doi-asserted-by":"crossref","first-page":"767","DOI":"10.2307\/25750704","article-title":"Improving employees\u2019 compliance through information systems security training: An action research study.","volume":"34","author":"P.Puhakainen","year":"2010","journal-title":"Management Information Systems Quarterly"},{"key":"joeuc.2013100104-39","doi-asserted-by":"crossref","first-page":"499","DOI":"10.1177\/001872677002300601","article-title":"Three dilemmas of action research.","volume":"23","author":"R.Rapaport","year":"1970","journal-title":"Human Relations"},{"key":"joeuc.2013100104-40","unstructured":"SafeNet. (2010). Strong authentication: Securing identities and enabling business white paper. Retrieved June 18, 2012, from http:\/\/www.safenet-inc.com\/data-protection\/authentication\/pki-authentication\/"},{"key":"joeuc.2013100104-41","unstructured":"SanNicolas-Rocca, T., & Olfman, L. (2009). Implementing two-factor authentication within higher education. In Proceedings of the Fourth Annual AIS SIGSEC Workshop on Information Security & Privacy (WISP), Phoenix, AZ."},{"key":"joeuc.2013100104-42","doi-asserted-by":"crossref","DOI":"10.4135\/9781412986137","author":"E.Schein","year":"1987","journal-title":"The clinical perspective in fieldwork"},{"key":"joeuc.2013100104-43","author":"B.Schneier","year":"2000","journal-title":"Secrets and lies: Digital security in a networked world"},{"key":"joeuc.2013100104-44","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2004.01.002"},{"issue":"1","key":"joeuc.2013100104-45","doi-asserted-by":"crossref","first-page":"32","DOI":"10.4018\/joeuc.1999010104","article-title":"Rethinking end-user training strategy: Applying a hierarchical knowledge-level model.","volume":"11","author":"M.Sein","year":"1999","journal-title":"Journal of End User Computing"},{"issue":"4","key":"joeuc.2013100104-46","first-page":"68","article-title":"Probing user-end IT security practices \u2013 via homework.","volume":"27","author":"S.Smith","year":"2004","journal-title":"EDUCAUSE Quarterly"},{"key":"joeuc.2013100104-47","doi-asserted-by":"publisher","DOI":"10.2307\/2392581"},{"key":"joeuc.2013100104-48","author":"G. L.Susman","year":"1983","journal-title":"Action research: A sociotechnical systems perspective"},{"key":"joeuc.2013100104-49","unstructured":"Tulu, B., & Chatterjee, S. (2003). A new security framework for HIPAA-compliant health information systems. In Proceedings of the Ninth Americas Conference on Information Systems, Tampa, FL."},{"key":"joeuc.2013100104-50","doi-asserted-by":"crossref","unstructured":"Tulu, B., Li, H., Chatterjee, S., Hilton, B., & Horan, T. (2005). Implementing digital signatures for healthcare enterprises; the case of online disability evaluation reports. International Journal of Healthcare Technology Management, 6(4\/5\/6), 470-488.","DOI":"10.1504\/IJHTM.2005.006992"},{"key":"joeuc.2013100104-51","doi-asserted-by":"publisher","DOI":"10.4018\/joeuc.2012010102"},{"key":"joeuc.2013100104-52","unstructured":"Ziemba, M. (2001). A training framework for the department of defense public key infrastructure. Unpublished master\u2019s thesis, Naval Postgraduate Institute."}],"container-title":["Journal of Organizational and End User Computing"],"original-title":[],"language":"ng","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=100014","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,1]],"date-time":"2022-06-01T23:00:00Z","timestamp":1654124400000},"score":1,"resource":{"primary":{"URL":"https:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/joeuc.2013100104"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2013,10,1]]},"references-count":53,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2013,10]]}},"URL":"https:\/\/doi.org\/10.4018\/joeuc.2013100104","relation":{},"ISSN":["1546-2234","1546-5012"],"issn-type":[{"value":"1546-2234","type":"print"},{"value":"1546-5012","type":"electronic"}],"subject":[],"published":{"date-parts":[[2013,10,1]]}}}