The Potential of Gaming to Ameliorate Human Factors in Information Security Compliance
David Thornton · Advances in information security, privacy, and ethics book series · 2022
In this chapter, the author discusses the need for appropriate training to improve information security compliance and some of the human factors that lead to non-compliance. Following is a section on theories that attempt to model and predict compliance. The author discusses the use of serious games, games-based learning, and gamification as educational tools, and their strengths in providing some of the major training needs, including emotional engagement, intrinsic motivation, repetition, discussion, reflection, and self-efficacy. This is followed by a list of some prominent games and gamification tools in the field of information security. Finally, the author concludes with guidelines and considerations for information security professionals who may be considering the use of serious games and gamification to enhance their information security awareness training.