BRIEF RESEARCH REPORT article

Front. Psychol., 08 September 2022

Sec. Educational Psychology

Volume 13 - 2022 | https://doi.org/10.3389/fpsyg.2022.986561

Risk management in digitalized educational environments: Teachers’ information security awareness levels

  • Department of Computer Education and Instructional Technology, Near East University, Nicosia, Cyprus

Abstract

With the spread of Information and Communication Technologies (ICT) tools and the Internet, Twenty first century technologies have significantly affected human life, and it has been desired to be obtained continuously. It has become challenging to protect information due to the increase in the methods by which malicious people can get information. As a result, it is crucial to determine people’s awareness levels by revealing the risks and threats to information security. In this context, a study was conducted to show the awareness levels of teachers who come after the family in raising conscious individuals in society. For this purpose, a quantitative research method was adopted for the problem and sub-problems that form the basis of the research. The survey model, one of the research designs used within the framework of the quantitative research method, was used. Information Security Awareness Scale was applied to 394 teachers, and according to the results obtained, it was determined that the information security awareness level of the teachers was moderate. According to the attacks and threats sub-dimension, which includes technical issues, it has been determined that the awareness levels of the teachers are at a medium level. The study results show that female teachers’ information security awareness levels are lower than male teachers. In comparison, the awareness levels of those who received information security awareness training and information technology teachers are higher.

Introduction

Until the twentieth century, investments that required physical infrastructures such as land and factories were replaced by information from the twenty-first century (). With the spread of computers, smart devices, and the Internet, twenty-first century technologies have penetrated almost all areas of human life, and as a result, information has become even more valuable and obtained its value (Yıldız Korkmaz and Atasoy, 2016; Grusho et al., 2018). The classic combination of companies, states, institutions, individuals, and societies in the twenty-first century is that they live in the information age and must keep up with the information age requirements (Lin, 2021).

As of 2022, 67.1% of the 7.91 billion population worldwide are mobile phone users, 62.5% are internet users, and 58.4% are social media users (). This indicates that we are faced with a digitalized world, and as a result, data production has reached an incredible speed (). It is essential to transform the produced data into information by making it functional (Fukuyama, 2018) and for society. A strong community is formed with the correct use of information (Park, 2017). In addition, various difficulties and social problems can be solved for the community (Sajidan et al., 2020). The sustainability of a strong community can be achieved with the correct use of technology (). The proper use of technology means integrating society with artificial intelligence, networked control, the Internet of things, provision of services with technology, robots, and cyber security (Nagahara, 2019). In addition, European Union countries have drawn attention to the importance of cyber security for sustainable development, stating that cyber security is a basic need in a sustainable society (Sulich et al., 2021). Cyber security is crucial because it protects information ().

With Information and Communication Technologies (ICT) tools, people can access information easily (Ghafir et al., 2018) and fast (Rahmatullah et al., 2022) at home, school, and the workplace (Ortaş, 2018). This situation has also increased the number of threats to information security (Jouini et al., 2014; Irmak and Baz, 2019). Human-made threats sometimes cause risks in information security breaches and occasionally natural disasters (Metalidou et al., 2014; Yaşar and Çakır, 2015). Human is the most crucial factor in information security (, ). It is impossible to talk about the successful provision of information security without human beings (; ). The human factor is why many cyber-attacks on computers and systems are successful (Hughes-Lartey et al., 2021). The attacks on people sometimes result from the negligence, ignorance, and carelessness of the user (Yaşar and Çakır, 2015) and sometimes from users abusing their authority (Parsons et al., 2014; Ghafir et al., 2018). When the information security breach incidents experienced by world-renowned IT companies in recent years are examined in detail, it has been seen that the primary source of the problem is the lack of awareness of the employees on information, information technologies, and information security (Khando et al., 2021).

To continue education and training after the closure of schools during the pandemic, 18 million 241 thousand 881 students and 1 million 117 thousand teachers started the distance education process in schools affiliated with the Ministry of National Education in Turkey on March 23, 2020. The process was provided through the Education Information Network (EBA) platform. According to the 2021 global digitalization report, the EBA platform used in distance education is one of the most hit pages in Google searches (Özok and Tayiz, 2020). Technological tools are used intensively at all levels, from primary to high school (Özok and Tayiz, 2020). This is because digital media is moving extensive data around the Internet (), causing concern for data security and increased risk (Lewandowski, 2019; Gökçearslan et al., 2021). Factors drivi Baryannis ng trouble are the disclosure of personal information, exposure to inappropriate online content, online security risks, and threats to the use of the Internet and smart devices (Kritzinger, 2017). It is necessary to eliminate anxiety to ensure the sustainability of digitalized educational environments and reduce the risks.

Literature review

Information security

Information security is the safe delivery of information to the recipient without being seized by unauthorized persons (Höne and Eloff, 2002; ). Its security must be ensured to protect the information (; Grusho et al., 2018). In this context, it is necessary to protect the privacy, security, and accessibility components that form the basis of information security (Tchernykh et al., 2019). Providing information security, minimizing risks to information security, widespread use of the Internet (), increasing the number of cyber-attack methods (Jang-Jaccard and Nepal, 2014), and establishing a legal basis by lawmakers (İhtiyaroğlu, 2020) have become mandatory (Henkoğlu and Yılmaz, 2013).

Risk management

Risk is defined as “suffering loss,” while risk management is defined as “the process of carefully and in detail identifying and evaluating the risks that may occur while performing the work of institutions or businesses in advance and taking measures to eliminate or minimize risks” (TDK, 2022). From an information security perspective, the risk is when a threat exploits a vulnerability to damage information or data (; ISO-ISO/IEC, 2008; Khidzir et al., 2010). In other words, the loss of confidentiality, integrity, and availability are the essential components of information security (Yeboah-Boateng, 2013). Risk management is a concept of increasing importance (Öznacar and Dagli, 2016) and can be defined as identifying potential risk (Spears and Barki, 2010) and reducing it to an acceptable level (Spears and Barki, 2010; Tummala and Schoenherr, 2011) and ensuring that it remains at this level. The definition of an acceptable level in risk management is not fully defined (Fan and Stevenson, 2018; ). Based on the definition, it can be stated that the acceptable level is the protection of the confidentiality, integrity, and accessibility components that form the basis of information security.

Digitalized education environment

Today, with the rapid development of information technology, the internet and technological products are used to research information and share ideas (Mashhadi and Kargozari, 2011). As a result, the fact that information is accessible at any time regardless of space and time has transformed the existing educational environments through the innovative structure of the age (Tılıç, 2020). As a result of this transformation, access to learning and educational resources can be at any time and place.

Information security in educational institutions

It is seen that attacks on educational institutions have increased with the transfer of the education and training environment to online environments due to the pandemic (Waldman, 2020; William, 2020; Levin, 2021). Attackers target schools due to the high number of people in the school and easier access to personal accounts (Richardson et al., 2020). In addition, on the cyber map published by Checkpoint, a world-renowned security product, educational institutions are the most targeted by attackers (). In this context, information security is essential in educational institutions to prevent attacks against teachers and students in online environments. Security risks can be eliminated by revealing teachers’ information security awareness levels (; ).

Information security awareness

The term “information security awareness” implies that users in an organization are ideally aware of their commitment to their security mission (Siponen, 2000; Kajzer et al., 2014). Minimizing security-related risks with awareness and maximizing the effectiveness of security techniques and procedures (Hart et al., 2020) have an important place in increasing the protection of information and data (). To create this awareness, finding users who have received information security awareness training is essential. These users are critical to reducing threats within the organization (). It is essential to increase their awareness and provide an educational environment to eliminate or minimize the vulnerabilities caused by the human factor in information security (Kim, 2014; ; ).

Teachers’ awareness

The sustainability of digitalized educational environments is essential in terms of the correct use of technology (Öznacar, 2018). Teachers are responsible for raising future citizens in a sustainable society (). Teachers need to be trained on information security and many other issues. However, some studies on teachers have shown that the level of awareness is not good enough (; ). However, it has been noted that efforts to raise teachers’ awareness are limited to some institutional publications, announcements, and informative websites; thus, these attempts lack interaction with the target audience of teaching (Kadıoğlu, 2019).

Hypotheses

The human factor is essential in managing information security properly (Yerby and Floyd KevinFloyd, 2018; Odiaga et al., 2020). Protecting information and data is possible by ensuring that users are aware of information security and thus minimizing potential risks (). People’s level of information security, which is seen as the weakest link of information security, is directly related to awareness (; Rezgui and Marks, 2008; Vardal, 2009). While more than half of the world’s population uses computer technology and communication technologies, it is essential how aware people are of the risks they may face (Gümüş, 2007; Keser and Güldüren, 2015). In this way, ensuring information security and minimizing risks is possible by raising awareness of people and using technological equipment correctly (Puhakainen, 2006; Şahinaslan et al., 2009; ). Especially in the information society we live in, in the age of technology where every field is rapidly digitalized, the level of information security awareness of teachers should be revealed in terms of following the developments, informing the society about the developments, and preparing them for the future. In this context, teachers’ information security awareness levels have been determined in previous studies, and the effects of different variables have been revealed. In the study conducted by , it was determined that the information security awareness levels of teachers were slightly above the middle level, and according to the gender and branch variables, the results were in favor of male teachers, and in the branch variable, results were obtained in favor of Information Technologies teachers. In the study by Keser and Yayla (2021), it was found that teachers’ information security awareness levels were high and male teachers had higher awareness levels than female teachers. According to the branch distribution, it was determined that the awareness levels of Information Technologies teachers were higher than in other branches. The fact that the awareness levels of teachers who received awareness training were higher than those who did not is one of the results of this study (Keser and Yayla, 2021). Odiaga et al. (2020) found that teachers had little or no knowledge about basic information security awareness practices, roles, threats, risks, and attacks. The study by Kiss (2019) determined that pre-school teachers’ information security awareness levels were low. According to the results obtained in the study by Karabatak and Karabatak (2019) on administrators working in schools, it was determined that administrators’ information security awareness levels were slightly above the middle level. The same study also found that the awareness levels of male administrators were higher than the awareness levels of female administrators (Karabatak and Karabatak, 2019). Considering these studies, it is seen that studies on teachers’ awareness determination are limited (; ).

In this study, the following hypotheses were put forward based on previous research by applying the information security awareness scale to determine the information security awareness levels of primary and secondary school teachers working city of Amasya in Turkey:

H1: Teachers’ information security awareness levels are at a medium level.

H2: Information security awareness levels of teachers differ according to gender.

H3: Information security awareness levels of teachers differ according to their training status.

H4: Information security awareness levels of teachers differ according to their branches.

Methodology

Research design

In this study, the survey model, one of the quantitative research designs, was used for the problem and sub-problems that form the basis of the research. The purpose of using this model (Wallen and Fraenkel, 2013), which is used to collect data on the opinions, attitudes, and behaviors of individuals on a subject and to reveal the general structure of these individuals on the subject, is to determine the information security awareness levels of teachers and to examine their awareness levels in detail in terms of different variables.

Sample

Based on the study population determined within the scope of this study, a study group was formed with the convenience sampling technique (Yıldırım and Şimşek, 2008). The convenient sampling method was preferred because it is flexible in terms of time and economy. In addition, easy-to-reach participants were included because participation in the research is voluntary, and it accelerates the research (Yıldırım and Şimşek, 2008). Within the scope of the research, 394 primary and secondary school teachers were reached, and participation in the data collection tool was voluntary in city of Amasya in Turkey.

Instrument

The “Information Security Awareness Scale” developed by was used to obtain data from the participants. The scale has a three-factor structure and consists of 48 items. In the development of the scale, exploratory factor analysis was conducted using a study group of 316 participants, and it was determined that it consisted of 48 items under three dimensions. Subsequently, confirmatory factor analysis was applied to 200 participants, and the structure was confirmed. The overall reliability coefficient of the scale is 0.98. As the overall score on the scale and the scores for sub-factors increase, participants’ Information Security Awareness increases. The scale score ranges are shown in Table 1.

TABLE 1

QuestionsLowest scoreHighest scoreLowMediumNormalHigh
Color coding
Information security awareness scale1–484824048–9697–144145–192193–240
Sub-factors
General security1–13136513–2627–3940–5253–65
Attack and threats14–30178517–3435–5152–6869–85
Mobile devices, privacy and communication31–48189018–3619–5455–7273–90

Information security awareness scale and the lowest, highest scores and level ranges.

Colors meaning: If it is blue, the teacher awareness’ level is low; If it is green, the teacher awareness’ level is medium; If it is yellow, the teacher awareness’ level is normal; If it is red, the teacher awareness’ level is high.

Data were collected in 3 months covering May and July 2021, after obtaining the necessary ethics committee permission to obtain the data. The data collection process was carried out meticulously to determine the awareness of information security, as teachers had to continue their classes online due to the mandatory closures and restrictions experienced during the pandemic process.

Data analysis

The study used Kolmogorov-Smirnov (KS) and skewness-kurtosis coefficients to determine whether the data showed a normal distribution. Shapiro-Wilks is used when the group size is less than 50, and KS is used when it is more than 50 (Kim and Park, 2019). KS test and skewness-kurtosis coefficients showed that the data showed normal distribution. In this context, descriptive statistics were applied for the first hypothesis, an independent t-test for the second and third hypotheses, and one-way ANOVA test for the fourth hypothesis.

Sample characteristics

According to the personal information obtained from the teachers, 52.3% of the teachers are female, and 47.7% are male. 26.1% stated that they received training, while 73.9% stated that they did not receive training. According to the branch distribution of the participants, 30.7% Classroom Teachers, 7.4% Pre-school, 4.8% Special Education, 4.6% Science, 5.8% Social Studies, 4.6% Religious Culture and Moral Knowledge, 7.1% Turkish, 5.8% English, 4.3% Information Technologies, 3.6% Physical Education, 4.3% Mathematics, 2.3% Turkish Language and Literature, 3.3% Technology Design, 4.1% Guidance, and 7.4% Vocational Branch teachers.

Research limitations

The study is limited to 364 primary and secondary school teachers for 3 months between May and July 2021. The study obtained results with gender, information security training status, and branch variables.

Results

Teachers’ information security awareness levels and score distribution by sub-factors is shown in Table 2. According to the Information Security Awareness Scale, teachers’ overall score average is 144.78+38.87, which is “medium.” The general security sub-factor score averages are 45.50+9.42, the attack and threats sub-factor score average are 43.40+15.91, and the mobile devices, privacy, and communication sub-factor score average is 55.88+16.61. The awareness level of general security and mobile devices, privacy, and communication sub-factors is “normal.” However, the level of the attacks and threats sub-factor was determined as “medium.” The averages of the items belonging to this factor are, respectively; Average score of “I know what hoax is” 2.52+1.13, average score of “I know how to deal with chain email” is 2.68+1.12, “Spyware (spyware) average score of 2.74+1.14, average score of” “I can tell if there is spyware on my computer” 2.43+1.09, average score of “I know how to prevent spyware from being installed on my computer” is 2.41+1, Average score of 1, “I know about security measures against identity theft” is 2.63+1.14, “I know what fake virus protection software is.” Average score of 2.59+1.13, average score of “I know what a Denial of Service (DoS) attack” is 2.26+1.07, average score of “I know what a phishing attack is” is 2.34+ Average score of 1.07, “I know what a social engineering attack is” 2.28+1.05, average score of “I know how to act to avoid being attacked by social engineering” is 2.29+1.04, “Cyberbullying (I know what cyberbullying is)” average score is 3+1.19, “I know how to protect myself against cyberbullying” average score is 2.83+1.2, “I know how to protect children against cyberbullying” average score is 2.82+1, 18, “I know the security measures to be taken against attacks that personal digital assistants (PDAs) may be exposed to” average score is 2.41+1.05, “I know what the active content used in web pages is for” average score is 2.49+ 1.06, “I know what cookies are used on web pages” her average score is 2.69+1.09.

TABLE 2

NMinMaxSd
Awareness levels39457.00240.00144.7838.87
General security39415.0065.0045.509.42
Attack and threats39417.0085.0043.4015.91
Mobile devices, privacy, and communication39418.0090.0055.8816.61

Teachers’ information security awareness levels and score distribution by sub-factors.

Colors meaning: If it is green, the teacher awareness’ level is medium; If it is yellow, the teacher awareness’ level is normal.

Teachers’ information security awareness levels and sub-factors relations by gender is shown in Table 3. As a result of the independent t-test conducted to determine whether there is a significant difference between teachers’ information security awareness levels and sub-factors with gender, a significant difference was determined between teachers’ awareness levels and gender. Male teachers’ awareness levels are higher than female teachers. In addition, male teachers’ awareness levels are higher in sub-factors than female teachers’ awareness levels.

TABLE 3

GendernStP
Information security awareness levelsFemale206136.4538.11−4.5640.00*
Male188153.9237.73
General securityFemale20643.429.21−4.7020.00*
Male18847.779.14
Attack and threatsFemale20640.3215.18−4.1130.00*
Male18846.7916.05
Mobile devices, privacy, and communicationFemale20652.7116.72−4.0380.00*
Male18859.3515.81

Teachers’ information security awareness levels and sub-factors relations by gender.

“*” is mean shows that it is significant. P < 0.05.

Teachers’ information security awareness levels and sub-factors relations by receiving education on information security is shown in Table 4. As a result of the independent t-test conducted to determine whether there is a significant difference between teachers’ information security awareness levels and sub-factors and their status of receiving education on information security, information security awareness levels of teachers who received training on awareness are higher than those who did not.

TABLE 4

EducationnStP
Information security awareness levelsYes103168.203937.662427.6090.00*
No291136.501735.85982
General securityYes10351.00978.643827.3560.00*
No29143.54988.91493
Attack and threatsYes10352.242717.208906.9370.00*
No29140.281814.19821
Mobile devices, privacy, and communicationYes10364.951514.719196.8100.00*
No29152.670116.06885

Teachers’ information security awareness levels and sub-factors relations by receiving education on information security.

“*” is mean shows that it is significant. P < 0.05.

Teachers’ information security awareness levels and sub-factors relations by branch is shown in Table 5. As a result of the one-way ANOVA test conducted to determine the significant difference between teachers’ information security awareness levels and sub-factors and their branches, as a result of the data obtained, the information security awareness levels of information technology branch teachers are higher than other branch teachers.

TABLE 5

nSdFpDifferences
Information security awareness levelsClassroom teaching121139.7839.415.8770.000Information Technologies Branch—All other branches
Pre-school29134.2836.14
Special education19138.3245.01
Science18133.9538.96
Social studies23151.4836.1
Religion and moral knowledge18137.1224.3
Turkish28134.9730.36
English23155.8732
Information technologies1721232.37
Physical education14170.8633.38
Maths17143.6520.64
Turkish language and literature9131.4542.97
Technology design13135.734.07
Counseling16147.1328.88
Others29142.9736.64
General securityClassroom teaching12145.2710.213.8910.000Information Technologies Branch—All other branches
Pre-school2942.6910.44
Special education1943.1110.75
Science1844.58.71
Social studies2345.929.96
Religion and moral knowledge1846.125.34
Turkish2843.337.45
English2346.317.61
Information technologies1758.656.68
Physical education14526.54
Maths1743.425.49
Turkish language and literature942.2311.08
Technology design13428.4
Counseling1645.696.71
Others2945.118.27
Attack and threatsClassroom teaching12142.0315.276.3420.000Information Technologies Branch—All other branches
Pre-school2939.1813.04
Special education1940.3217.32
Sciences1839.2815.72
Social sciences2346.4415.12
Religion and moral knowledge1836.7312.77
Turkish2839.7512.64
English2346.6614.38
Information technologies1772.3615.21
Physical education1452.5815.28
Maths1744.0610.73
Turkish language and literature936.7816.39
Technology design1339.7715.74
Counseling1643.7510.61
Others2942.4515.03
Mobile devices, privacy and communicationClassroom teaching12152.4917.674.9200.000Information Technologies Branch - All Other Branches
Pre-school2952.4215.99
Special education1954.919.4
Sciences1850.1717.34
Social sciences2359.1413.97
Religion and moral knowledge1854.2811.39
Turkish2851.914.27
English2362.9212.65
Information technologies178111.7
Physical education1466.2913.06
Maths1756.187.62
Turkish language and literature952.4518.52
Technology design1353.9312.2
Counseling1657.6915.4
Others2955.4215.08

Teachers’ information security awareness levels and sub-factors relations by branch.

Discussion

Teachers were expected to use technology quickly during the pandemic, produce materials that would enable students to learn, and be executives that will enable students to learn (Rapanta et al., 2020). Due to the mandatory closures experienced during the pandemic, education took place in digital environments, and as a result, the learning process has become more digital (Frolova et al., 2020). However, due to the focus on the execution of the process, research on concepts such as safety and possible risk situations has not been revealed (). In this context, providing safer educational environments and raising awareness of attacks on information security that teachers may encounter is essential in the sustainability and risk management of digitalized educational environments.

H1: Teachers’ information security awareness levels are at a medium level.

As a result of the findings, teachers’ information security awareness levels were determined as “moderate.” This result is in line with the result of Kubacka et al. (2021) during the pandemic process. Among the studies conducted before the pandemic, also found a moderate level of awareness in the study conducted for teachers. However, in the study by Keser and Yayla (2021), it was determined that teachers’ information security awareness levels were high. While awareness levels of general security, mobile devices, privacy, and communication factors from sub-factors were at a “normal” level, the awareness level of attacks and threats sub-factor was determined as a “medium” level. When the items belonging to the factor are examined, it is seen that it contains technical terms. Teachers need to be more aware of attacks and threats in this context. Similar results were obtained in the studies of Filippidis et al. (2018). The participants, whose awareness level was average, pointed out that they needed to improve their awareness of the technical details of information security and the tools used in this field (Filippidis et al., 2018). The awareness levels of teachers who educate the future generations must be even higher to protect educational institutions, which are, in the first place, the target of attackers. It has been determined that teachers do not have sufficient knowledge about cyber-attacks, information theft, social engineering attacks, and malware, which are increasing daily. This situation can be interpreted as inadequate security of information in educational institutions.

H2: Information security awareness levels of teachers differ according to gender.

A relationship was found between gender and information security awareness level, general security, mobile devices, privacy, and communication factors sub-dimensions. It has been determined that the awareness level of women is lower than men in both the general scores and sub-factors obtained from the scale. One of the similar results obtained in the study is that there is a strong link between gender and awareness and that men have higher awareness levels than women (Farooq et al., 2015; Karabatak and Karabatak, 2019; ; Keser and Yayla, 2021). The reason why information security awareness levels are in favor of males can be interpreted as male teachers using ICT tools more (Gudmundsdottir and Hatlevik, 2018). In addition, when we look at the statistics on the use of the Internet and ICT tools in Turkey, it is clear that men use ICT tools more than women ().

H3: Information security awareness levels of teachers differ according to their training status.

Many studies demonstrate the importance of information security education (; Zwilling et al., 2020; Hwang et al., 2021; Khando et al., 2021; Taha and Dahabiyeh, 2021). In these studies, training for information security reveals the importance of training in raising conscious individuals to ensure information security, preventing attacks against end users, and raising awareness about attack types. The fact that those who receive awareness training have higher levels of information security reveals the importance of receiving training on information security.

H4: Information security awareness levels of teachers differ according to their branches.

A significant difference was found between the branches of the teachers and the information security awareness levels and the sub-dimensions of general security, mobile devices, privacy, and communication factors. The difference is in favor of the Information Technologies Branch. There are studies supporting this result in the literature (; Keser and Yayla, 2021). It can be thought that the awareness levels of Information Technologies teachers are higher because they closely follow the technology due to their professional definitions and have a better command of the terms about information security.

In summary, it is essential to continue education safely () to minimize the risks of possible attacks in digitalized educational environments. In this context, protecting information with the measures to be taken for information security in educational environments means ensuring risk management. Considering this situation, in this study, teachers’ information security awareness levels were determined, and the effect of different variables was examined. The results obtained were discussed and presented to the literature.

Recommendations

Information security is a concept that is the responsibility of every individual user of ICT. Due to the increase in the methods of malicious people to obtain information, institutions and organizations should pay more attention to information security awareness training. Training on information security should be provided within a scope that includes all individuals from an early age. Efforts should be made to increase the tendencies of women toward information security by ensuring that they participate more in the process. Since information technology teachers closely follow the concepts related to technology and technological developments, it is recommended that they increase the associations of learning outcomes and in-class activities related to these concepts in educational environments.

Statements

Data availability statement

The datasets presented in this study can be found in online repositories. The names of the repository/repositories and accession number (s) can be found in the article/supplementary material.

Ethics statement

The studies involving human participants were reviewed and approved by the Ethical Committee Board of Near East University. The patients/participants provided their written informed consent to participate in this study.

Author contributions

HS wrote the introduction, method, findings, discussion, conclusion, and suggestions in line with the opinions and suggestions of SK. As a result, this study has obtained a result of the approval and contributions of both authors.

Acknowledgments

This study was from HS doctoral thesis under the supervision of SK.

Conflict of interest

The authors declare that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.

Publisher’s note

All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article, or claim that may be made by its manufacturer, is not guaranteed or endorsed by the publisher.

References

  • 1

    AhlanA. R.LubisM.LubisA. R. (2015). Information security awareness at the knowledge-based institution: Its antecedents and measures.Procedia Comput. Sci.72361373. 10.1016/j.procs.2015.12.151

  • 2

    AkcilU.BastasM. (2021). Examination of university students’ attitudes towards e-learning during the COVID-19 pandemic process and the relationship of digital citizenship.Contemp. Educ. Technol.13113. 10.30935/cedtech/9341

  • 3

    AkgünÖE.TopalM. (2015). Eğitim fakültesi son sınıf öğrencilerinin bilişim güvenliği farkındalıkları: Sakarya üniversitesi eğitim fakültesi örneği.Sakarya Univ. J. Educ.598121. 10.19126/suje.73391

  • 4

    al AwawdehS.TubaishatA. (2014). “An information security awareness program to address common security concerns in IT unit,” in ITNG 2014 - Proceedings of the 11th international conference on information technology: New generations, Las Vegas, NV. 273278. 10.1109/ITNG.2014.67

  • 5

    AlacadağlıE. (2019). Bilgi Yönetimi, Dijitallşem ve Türk SAğlık Sistemi.J. Turkish Stud.146786. 10.7827/TurkishStudies.14918

  • 6

    AldawoodH.SkinnerG. (2019). “Educating and raising awareness on cyber security social engineering: A literature review,” in Proceedings of 2018 IEEE international conference on teaching, assessment, and learning for engineering TALE, (Wollongong, NSW), 6268. 10.1109/TALE.2018.8615162

  • 7

    Al-JanabiS.Al-ShourbajiI. (2016). A study of cyber security awareness in educational environment in the middle east.J. Inf. Knowl. Manage.15:1650007. 10.1142/S0219649216500076

  • 8

    Al-ShehriY. (2012). Information security awareness and culture.Br. J. Arts Soc. Sci.620469578.

  • 9

    ArinaA.AnatolieA. (2021). Cyber security threat analysis in higher education institutions as a result of distance learning.Int. J. Sci. Technol. Res.10128133.

  • 10

    AslayF. (2017). Siber saldiri yöntemleri ve türkiye’nin siber güvenlik mevcut durum analizi.Int. J. Multidiscip. Stud. Innov. Technol.12428.

  • 11

    AvcıÜOruçO. (2020). Üniversite öğrencilerinin kişisel siber güvenlik davranişlari ve bilgi güvenliği farkindaliklarinin incelenmesi.İnönü Üniversitesi Eğitim Fakültesi Dergisi21284303. 10.17679/inuefd.526390

  • 12

    Baena-MoralesS.Martinez-RoigR.Hernádez-AmorósM. J. (2020). Sustainability and educational technology—A description of the teaching self-concept.Sustainability12:103091210309. 10.3390/su122410309

  • 13

    BaryannisG.ValidiS.DaniS.AntoniouG. (2019). Supply chain risk management and artificial intelligence: State of the art and future research directions.Int. J. Prod. Res.5721792202.

  • 14

    BaykaraM.DaşR.KaradoğanI. (2013). “Bilgi güvenliği sistemlerinde kullanılan araçların incelenmesi,”Proceedings of the 1st International Symposium on Digital Forensics and Security (ISDFS’13), Vol. 20. 21.

  • 15

    BogartK. J. (2012). Information Security Awareness: How to Get Users Asking for More. Accessed date 20.03.2022 from https://silo.tips/download/information-security-awareness-how-to-get-users-asking-for-more.

  • 16

    BostanA.ŞengülG. (2018). Siber güvenlik farkindaliği oluşturma. in siber güvenlik ve savunma farkindalik ve caydiricilik.Ankara: Grafiker Yayınları, 145158.

  • 17

    BubenkoJ. A. (2007). “From information algebra to enterprise modelling and ontologies — a historical perspective on modelling for information systems,” in Conceptual Modelling in Information Systems Engineering, edsKrogstieJ.OpdahlA. L.BrinkkemperS. (Berlin: Springer), 118. 10.1007/978-3-540-72677-7_1

  • 18

    Çalış DumanM. (2022). Toplum 5.0: Ýnsan odakli dijital dönüşüm.Sosyal Siyaset Konferansları Dergisi/J. So. Policy Conf.19309336. 10.26650/jspc.2022.82.1008072

  • 19

    CanoğullarıE. (2021). Öğretmenlerin bilgi güvenliği konusundaki farkindaliklarinin incelenmesi.Kalem Uluslararasi Egitim ve Insan Bilimleri Dergisi11651679. 10.23863/kalem.2021.219

  • 20

    ÇetinkayaL.GüldürenC.KeserH. (2017). Öğretmenler için bilgi güvenliği farkindalik ölçeği(BGFÖ) geliştirme çalişmasi.Milli Eğitim Dergisi2163352.

  • 21

    Checkpoint (2022). Live Cyber Threat Map. Checkpoint. Available online at: https://threatmap.checkpoint.com/(accessed April 15, 2022).

  • 22

    ChouH. L.ChouC. (2016). An analysis of multiple factors relating to teachers’ problematic information security behavior.Comput. Hum. Behav.65334345. 10.1016/j.chb.2016.08.034

  • 23

    ColwillC. (2009). Human factors in information security: The insider threat–Who can you trust these days?Inf. Secur. Tech. Rep.14186196. 10.1016/j.istr.2010.04.004

  • 24

    CouldryN.MejiasU. A. (2019). Data colonialism: Rethinking big data’s relation to the contemporary subject.Telev. New Media20336349. 10.1177/1527476418796632

  • 25

    CoxA.ConnollyS.CurrallJ. (2001). Raising information security awareness in the academic setting.Vine311116. 10.1108/03055720010803961

  • 26

    Da VeigaA. (2019). “Achieving a security culture,” in Cybersecurity education for awareness and compliance, (Pennsylvania: IGI Global), 72100.

  • 27

    da VeigaA.AstakhovaL. V.BothaA.HerselmanM. (2020). Defining organisational information security culture—Perspectives from academia and industry.Comput. Secur.92:101713. 10.1016/j.cose.2020.101713

  • 28

    de BruijnH.JanssenM. (2017). Building cyber security Awareness: The need for evidence-based framing strategies.Gov. Inf. Q.3417. 10.1016/j.giq.2017.02.007

  • 29

    Digital. (2022). Another year of bumper growth. We are social UK. Available online at: https://wearesocial.com/uk/blog/2022/01/digital-2022-another-year-of-bumper-growth-2/(accessed June 13, 2022).

  • 30

    DlaminiM. T.EloffJ. H. P.EloffM. M. (2009). Information security: The moving target.Comput. Secur.28189198. 10.1016/j.cose.2008.11.007

  • 31

    EvansY.HeI. Y.JanickeH. (2018). “Analysis of published public sector information security incidents and breaches to establish the proportions of human error,” in Proceedings of the twelfth international symposium on human aspects of information security assurance, (HAISA), Dundee, Scotland, 191202.

  • 32

    EvansM.HeY.LuoC.YevseyevaI.JanickeH.ZamaniE.et al (2019). Real-time information security incident management: A case study using the IS-CHEC technique.IEEE Access7142147142175. 10.1109/ACCESS.2019.2944615

  • 33

    FanY.StevensonM. (2018). A review of supply chain risk management: Definition, theory, and research agenda.Int. J. Phys. Distrib. Logist. Manag.48205230.

  • 34

    FarooqA.IsoahoJ.VirtanenS.IsoahoJ. (2015). “Information security awareness in educational institution: An analysis of students’ individual factors,” in Proceedings of the 2015 IEEE Trustcom/BigDataSE/ISPA, (Helsinki), 352359. 10.1109/Trustcom.2015.394

  • 35

    FilippidisA. P.HilasC. S.FilippidisG.PolitisA. (2018). Information security awareness of greek higher education students - preliminary findings. 2018 7th international conference on modern circuits and systems technologies.Mocast201814. 10.1109/MOCAST.2018.8376578

  • 36

    FrolovaE. V.RogachO. V.RyabovaT. M. (2020). Digitalization of education in modern scientific discourse: new trends and risks analysis.Eur. J. Contemp. Educ.9313336. 10.13187/ejced.2020.2.313

  • 37

    FukuyamaM. (2018). Society 5.0: Aiming for a new human-centered society.Japan: 4750.

  • 38

    GhafirI.SaleemJ.HammoudehM.FaourH.PrenosilV.JafS.et al (2018). Security threats to critical infrastructure: the human factor.J. Supercomput.7449865002. 10.1007/s11227-018-2337-2

  • 39

    GökçearslanŞGünbatarM. S.SarıtepeM. (2021). Ortaöğretim öğrencilerinin bilgi güvenliği farkindaliklarinin incelenmesi.Yuzunci Yil Universitesi Egitim Fakultesi Dergisi18354373. 10.33711/yyuefd.867015

  • 40

    GrushoA. A.GrushoN. A.ZabezhayloM. I.TimoninaE. E. (2018). Protection of Valuable Information in Information Technologies.Automat. Control Comput. Sci.5210761079. 10.3103/S0146411618080138

  • 41

    GudmundsdottirG. B.HatlevikO. E. (2018). Newly qualified teachers’ professional digital competence: Implications for teacher education.Eur. J. Teach. Educ.41214231.

  • 42

    GümüşM. (2007). Kurumsal bilgi güvenliği yönetim sistemleri ve güvenliği.Istanbul: Yıldız Teknik Üniversitesi.

  • 43

    HartS.MargheriA.PaciF.SassoneV. (2020). Riskio: A serious game for cyber security awareness and education.Comput. Secur.95:101827. 10.1016/j.cose.2020.101827

  • 44

    HenkoğluT.YılmazB. (2013). Avrupa birliği (AB) bilgi güvenliği politikalari.Türk Kütüphaneciliği27451471.

  • 45

    HöneK.EloffJ. H. P. (2002). Information security policy - What do international information security standards say?Comput. Secur.21402409. 10.1016/S0167-4048(02)00504-7

  • 46

    Hughes-LarteyK.LiM.BotcheyF. E.QinZ. (2021). Human factor, a critical weak point in the information security of an organization’s Internet of things.Heliyon7:e06522. 10.1016/j.heliyon.2021.e06522

  • 47

    HwangI.WakefieldR.KimS.KimT. (2021). Security awareness_ the first step in information security compliance behavior.J. Comput. Inf. Syst.61345356. 10.1080/08874417.2019.1650676

  • 48

    ÍhtiyaroğluU. (2020). Bilişim sistemine girme suçunun yargi kararlari bağlaminda incelenmesi.Hacettepe Hukuk Fakültesi Dergisi10406440. 10.32957/hacettepehdf.726568

  • 49

    IrmakH.BazF. Ç (2019). Kurumsal bilgi güvenliği, tehditler ve alinmasi gereken önlemler üzerine inceleme. 2. Uluslararasi mardin artuklu bilimsel araştirmalar kongresi.Mardin: Farabi Yayınevi. 333341.

  • 50

    ISO-ISO/IEC. (2008). ISO - ISO/IEC 27005:2008 - Information technology — security techniques — Information security risk management.Geneva: ISO.

  • 51

    Jang-JaccardJ.NepalS. (2014). A survey of emerging threats in cybersecurity.J. Comput. Syst. Sci.80973993. 10.1016/j.jcss.2014.02.005

  • 52

    JouiniM.BenL.RabaiA.AissaB. (2014). Classification of security threats in information systems.Procedia Comput. Sci.32489496. 10.1016/j.procs.2014.05.452

  • 53

    KadıoğluE. A. (2019). Design, development and implementation of an information security and cyberethics course for pre-service teachers: A design-based research [Phd Thesis].Cankaya: Middle East Technical University.

  • 54

    KajzerM.DarcyJ.CrowellC. R.StriegelA.van BruggenD. (2014). An exploratory investigation of message-person congruence in information security awareness campaigns.Comput. Secur.436476. 10.1016/j.cose.2014.03.003

  • 55

    KarabatakS.KarabatakM. (2019). “Information security awareness of school administrators,” in 7th International Symposium on Digital Forensics and Security, (Barcelos: ISDFS), 10.1109/ISDFS.2019.8757525

  • 56

    KeserH.GüldürenC. (2015). Bilgi Güvenliği Farkındalık Ölçeği (BGFÖ) Geliştirme Çalışması.Kastamonu Üniversitesi Kastamonu Eğitim Dergisi2311671184.

  • 57

    KeserH.YaylaH. G. (2021). Fatih projesi uygulanan okullardaki ög̃retmenlerin bilgi güvenlig̃i farkındalık düzeylerinin incelenmesi.Millî Eg̃itim Dergisi50940.

  • 58

    KhandoK.GaoS.IslamS. M.SalmanA. (2021). Enhancing employees information security awareness in private and public organisations: A systematic literature review.Comput. Secur.106:102267. 10.1016/j.cose.2021.102267

  • 59

    KhidzirN. Z.MohamedA.ArshadN. H. (2010). Information security risk factors: Critical threats and vulnerabilities in ICT outsourcing.Proceedings - 2010 International Conference on Information Retrieval and Knowledge Management: Exploring the Invisible World, CAMP’Shah Alam10194199. 10.1109/INFRKM.2010.5466918

  • 60

    KimE. B. (2014). Recommendations for information security awareness training for college students.Inf. Manage. Comput. Secur.22115126. 10.1108/IMCS-01-2013-0005

  • 61

    KimT. K.ParkJ. H. (2019). More about the basic assumptions of t-test: Normality and sample size.Korean J. Anesthesiol.72331335. 10.4097/kja.d.18.00292

  • 62

    KissG. (2019). The information security awareness of the Slovakian kindergarten teacher students at starting and finishing the study in higher education.SHS Web Conf.66:01042. 10.1051/shsconf/20196601042

  • 63

    KritzingerE. (2017). Growing a cyber-safety culture amongst school learners in South Africa through gaming.S. Afr. Comput. J.291635. 10.18489/sacj.v29i2.471

  • 64

    KubackaA.BialyD.GolabR. (2021). Perception of information security in the process of distance learning during the COVID-19 pandemic on the example of university teachers’ experiences.Int. J. Res. E Learn.7118. 10.31261/IJREL.2021.7.2.05

  • 65

    LevinD. A. (2021). The state Of K-12 cybersecurity: 2020 year in review. Available online at: https://k12cybersecure.com(accessed March 18, 2022).

  • 66

    LewandowskiJ. (2019). “[PDF] intentionally secure: Teaching students to become responsible and ethical users | semantic scholar,” in Emerging trends in cyber ethics and education, ed.BlackburnI. L. P. R. (Indiana: IGI Global), 118130. 10.4018/978-1-5225-5933-7.ch006

  • 67

    LinF. (2021). “Big data platform for daily management of higher vocational students in the information age,”Proceedings of the 2021 International Symposium on Advances in Informatics, Electronics and Education (ISAIEE), (Germany: IEEE), 220223. 10.1109/ISAIEE55071.2021.00061

  • 68

    MashhadiV. Z.KargozariM. R. (2011). Influences of digital classrooms on education.Procedia Comput. Sci.311781183. 10.1016/j.procs.2010.12.190

  • 69

    MetalidouE.MarinagiC.TrivellasP.EberhagenN.GiannakopoulosG.SkourlasC. (2014). Human factor and information security in higher education.J. Syst. Inf. Technol.16210221. 10.1108/JSIT-01-2014-0007

  • 70

    NagaharaM. (2019). A research project of society 5.0 in kitakyushu.Hong Kong, China. 10.1109/CCTA.2019.8920449

  • 71

    OdiagaG. A.AbekaS.LiyalaS. (2020). An information security awareness framework for secondary school teachers in Kenya.Int. J. Innov. Res. Adv. Stud. (IJIRAS)78898.

  • 72

    OrtaşI. (2018). Bilgi ve iletişim çağinda bilimsel bilgiye erişimin önemi ve türkiye nin bilgiye erişim potansiyeli (In the information and communication age, the importance of accessing scientific information and the information and communication potential of Turkey).Turk Kutuphaneciligi - Turkish Librariansh.32223232. 10.24146/tkd.2018.39

  • 73

    ÖznacarB. (2018). “Risk management strategies in school development and the effect of policies on tolerance education,” in In open and equal access for learning in school management, (London: IntechOpen), 107114. 10.5772/intechopen.70787

  • 74

    ÖznacarB.DagliG. (2016). Evaluation of risks for school directors in education in developed/Developing countries.Anthropologist23110. 10.1080/09720073.2016.11891918

  • 75

    ÖzokH. I.TayizV. (2020). “Uzaktan eğitim ve teknoloji bağimliliği,” in Pandemi ve eğitim, (Ankara: Anı Yayıncılık), 293310.

  • 76

    ParkS. (2017). “Information is power,” in Digital capital, (London: Palgrave Macmillan), 161183. 10.1057/978-1-137-59332-0_8

  • 77

    ParsonsK.McCormacA.ButaviciusM.PattinsonM.JerramC. (2014). Determining employee awareness using the human aspects of information security questionnaire (HAIS-Q).Comput. Secur.42165176. 10.1016/j.cose.2013.12.003

  • 78

    PuhakainenP. (2006). Design theory for information security awareness [Master Thesis].Oulu: Unıversity Of Oulu.

  • 79

    RahmatullahA. S.MulyasaE.SyahraniS.PongpaliluF.PutriR. E. (2022). Digital era 4.0.Linguist. Cult. Rev.689107. 10.21744/lingcure.v6nS3.2064

  • 80

    RapantaC.BotturiL.GoodyearP.GuàrdiaL.KooleM. (2020). Online university teaching during and after the Covid-19 crisis: Refocusing teacher presence and learning activity.Postdigital Sci. Educ.2923945. 10.1007/s42438-020-00155-y

  • 81

    RezguiY.MarksA. (2008). Information security awareness in higher education: An exploratory study.Comput. Secur.27241253. 10.1016/j.cose.2008.07.008

  • 82

    RichardsonM. D.LemoineP. A.StephensW. E.WallerR. E. (2020). Planning for cyber security in schools: The human factor: Roadrunner search discovery service.Educ. Plan.27:17.

  • 83

    ŞahinaslanE.KantürkA.ŞahinaslanÖBorandağE. (2009). Kurumlarda bilgi güvenliği farkındalığı, önemi ve oluşturma yöntemleri.Akademik Bilişim91113.

  • 84

    SajidanS. S.PerdanaR.AtmojoI. R. W.NugrahaD. A. (2020). Development of science learning model towards society 5.0: A conceptual model.J. Phys. Conf. Ser.1511110. 10.1088/1742-6596/1511/1/012124

  • 85

    SiponenM. T. (2000). Conceptual foundation for organizational information security awareness.Inf. Manage. Comput. Secur.83141. 10.1108/09685220010371394

  • 86

    SpearsJ. L.BarkiH. (2010). User participation in information systems security risk management.MIS Q. Manage. Inf. Syst.34503522. 10.2307/25750689

  • 87

    SulichA.RutkowskaM.Krawczyk-JezierskaA.JezierskiJ.ZemaT. (2021). Cybersecurity and sustainable development.Procedia Comput. Sci.1922028. 10.1016/j.procs.2021.08.003

  • 88

    TahaN.DahabiyehL. (2021). College students information security awareness: A comparison between smartphones and computers.Educ. Inf. Technol.2617211736. 10.1007/s10639-020-10330-0

  • 89

    TchernykhA.SchwiegelsohnU.TalbiE.GhazaliBabenkoM. (2019). Towards understanding uncertainty in cloud computing with risks of confidentiality, integrity, and availability.J. Comput. Sci.36:100581. 10.1016/j.jocs.2016.11.011

  • 90

    TDK. (2022). Türk dil kurumu sözlükleri. Available online at: https://sozluk.gov.tr/(accessed August 10, 2022).

  • 91

    TılıçG. (2020). Eğitimde Dijitalleşme Kapsamında Oyunlaştırma Kavramı.Sanat ve Tasarım Dergisi, 26671695.

  • 92

    TummalaR.SchoenherrT. (2011). Assessing and managing risks using the Supply Chain Risk Management Process (SCRMP).Supply Chain Manage. Int. J.16474483. 10.1108/13598541111171165

  • 93

    VardalN. (2009). Yükseköğretimde bilgi güvenliği: Bilgi güvenlik yönetim sistemi için bir model önerisi ve uygulaması [Doktora].Washington, DC: Eğitim Bilimleri Enstitüsü.

  • 94

    WaldmanA. (2020). Cyber Attacks on Schools Tripled-Technology News. Available online at https://www.hurriyet.com.tr/teknoloji/okullara-yonelik-siber-saldirilar-uc-kat-artti-41612854. [Accessed date: March 18, 2022]

  • 95

    WallenN. E.FraenkelJ. R. (2013). Educational research: A guide to the process.Abingdon: Routledge.

  • 96

    WilliamT. (2020). K-12 Schools warned of increasing cyber-attacks in U.S. advisory - Bloomberg. Available online at: https://www.bloomberg.com/news/articles/2020-12-10/k-12-schools-warned-of-increasing-cyber-attacks-in-u-s-advisory(accessed March 18, 2022).

  • 97

    YaşarH.ÇakırH. (2015). Kurumsal siber güvenliğe yönelik tehditler ve önlemleri.Düzce Üniversitesi Bilim ve Teknoloji Dergisi3488507.

  • 98

    Yeboah-BoatengO. E. (2013). Cyber-security challenges with smes in developing economies: Issues of confidentiality, integrity & availability (CIA).Denmark: Aalborg University.

  • 99

    YerbyJ.Floyd KevinFloydK. (2018). Faculty and staff information security awareness and behaviors.J. Colloq. Inf. Syst. Secur. Educ. (CISSE)6123.

  • 100

    YıldırımA.ŞimşekH. (2008). Sosyal bilimlerde nitel araştirma yöntemleri. seçkin yayinlari.Ankara: Seçkin Yayınları.

  • 101

    Yıldız KorkmazN.AtasoyA. (2016). Öğrencilerde bilgi güvenliği farkindaliğinin değerlendirilmesi gönderim.Sağlıkta Performans ve Kalite Dergisi118195.

  • 102

    ZwillingM.KlienG.LesjakD.WiechetekŁCetinF.BasimH. N. (2020). Cyber security awareness, knowledge and behavior: A comparative study.J. Comput. Inf. Syst.62116. 10.1080/08874417.2020.1712269

Summary

Keywords

information security, awareness, teacher, risk management, sustainable society

Citation

Sapanca HF and Kanbul S (2022) Risk management in digitalized educational environments: Teachers’ information security awareness levels. Front. Psychol. 13:986561. doi: 10.3389/fpsyg.2022.986561

Received

05 July 2022

Accepted

16 August 2022

Published

08 September 2022

Volume

13 - 2022

Edited by

Ahmet Koç, Hittite University, Turkey

Reviewed by

Sayed Fayaz Ahmad, Institute of Business Management, Pakistan; Joao Mattar, Pontifical Catholic University of São Paulo, Brazil; Murat Tolga Kayalar, Erzincan Binali Yildirim University, Turkey

Updates

Copyright

*Correspondence: Hamza Fatih Sapanca,

This article was submitted to Educational Psychology, a section of the journal Frontiers in Psychology

Disclaimer

All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article or claim that may be made by its manufacturer is not guaranteed or endorsed by the publisher.

Outline

Cite article

Copy to clipboard


Export citation file


Share article

Article metrics