Need a 20 page APA paper --Chapter 3
Running head: GAMIFICATION FOR IT SECURITY TRAINING 1
GAMIFICATION FOR IT SECURITY TRAINING 5
Impact of Gamification on IT Security Training Comment by Jess Schwartz: This chapter is missing the required section headings. The headings are found in the chapter 3 template. Please be sure to download the template and insert all section headings into the appropriate areas of your chapter 3.
Chapter-3: Methodology
The number of cyber-attacks has been increasing rapidly in organizations. These attacks can bring down organizations' reputation and can cause a loss of millions of dollars for the organizations. Most of the vulnerabilities, attacks, risks, and viruses result from a lack of security awareness of employees and users (Seaborn & Fels, 2015). These risks, vulnerabilities, and attacks can be reduced by improving employees' knowledge and skills in strengthening the companies' IT infrastructure. For this purpose, organizations can arrange several workshops and training sessions online and offline physically related to cyber-security awareness.
Many employees do not show interest and feel boredom in attending those workshops and training sessions. Gamification is considered a practice that can help boost employees' appeal and engagement levels during security awareness training. Gamification will positively impact the security training offered to employees by increasing their interest and engagement level. The main problem that will be addressed in this research is understanding the impact of gamification on the training session offered to employees for improving the security of IT infrastructure primarily related to cybersecurity because of increased risks.
These risks, vulnerabilities, and attacks can be reduced by enhancing employees' knowledge and skills in strengthening the companies' IT infrastructure. For this purpose, organizations can arrange several workshops and training sessions related to cyber-security awareness (Hart et al., 2020). Many employees do not show interest and feel boredom in attending those workshops and training sessions. Gamification is considered a practice that can help boost employees' interest and engagement levels during security awareness training.
The present research study is considered highly useful for finding the impact of gamification on employees' training sessions for improving the security of IT infrastructure. This study would enable organizations to understand the significance of gamification. It is one of the best approaches for increasing employee engagement and involvement in training sessions. Many employees feel difficulty and face a lack of interest and enthusiasm while attending the workshops and training sessions arranged by their employers and managers (Alotaibi et al., 2016).
The number of cyber-attacks has been increasing rapidly in organizations. These attacks can bring down organizations' reputation and cause a loss of millions of dollars. Most of the vulnerabilities, attacks, risks, and viruses result from a lack of security awareness of employees and users (Seaborn & Fels, 2015). Hence, gamification can be a highly effective technique for organizations to increase employees' interest and engagement levels in the offered workshops and training sessions (Baxter et al., 2016).
The present research study's primary purpose is to evaluate gamification's impact on employees' IT security training for spreading awareness about cybersecurity. For the current research, all the data would be collected from a mixed research method. Some data would be collected from the qualitative research method, and the remaining data would be collected from the quantitative research method to support the findings of secondary data collection. A survey and an interview would be conducted from the population's selected size for collecting primary data.
In recent years, there has been a significant increase in several types of security breaches, vulnerabilities, and flaws contributing to the rise in cybercrimes and terrorism. Cybercriminals have been taking advantage of those identified security flaws and breaches to attack companies' systems to take out confidential and useful information of customers and companies to negatively impact companies' reputation and get a financial advantage. Ransomware is one of the most commonly used by cybercriminals in which cybercriminals ask for money (Mathoosoothenen et al., 2017).
These significant numbers of vulnerabilities and security breaches have been identified and caused by human beings considered the real primary exposure in the Information Technology domain (Pattabiraman et al., 2018). It is highly essential for employees of companies and governmental institutions dealing with confidential data of customers to understand several types of risks and threats that can be regarding the malicious use of their information systems (Ruiz-Alba et al., 2019). Those companies and institutions need to take multiple remedial and preventive measures to reduce security breaches and leakage of data and information to cybercriminals.
For this purpose, the use of security awareness and training sessions is considered one of the critical methods used by companies and institutions to reduce cybercrimes and terrorism and build a highly competitive position in information technology (Redhead & Saunders, 2019). It helps increase participants' motivation, engagement, and interest in the offered workshops and training sessions. Companies can use multiple practices and approaches in which gamification is a highly effective practice (Thornton & Francia, 2014).
The present research study is being conducted to understand the positive and negative impacts of using the gamification technique in the Information technology sector to increase awareness about cybersecurity and provide training sessions to employees regarding Information Technology (Seaborn & Fels, 2015). The idea that would be studied in the current research study would be a long term and continuously used program for making any software application or mobile application based on multiple types of gaming to provide training and spread awareness among employees (Thornton & Francia, 2014). The current research study would also explore the factors that positively contributed to making the gamification approach a highly popular approach for increasing participants' engagement and interest levels by reducing their boredom in the offered workshops and training sessions.
Besides, the current research study would also discover why they have contributed to using a gaming-based learning approach more useful in Information Technology. It helps spread awareness about cybercrimes and terrorism and how employees can follow multiple types of practices and techniques to avoid security breaches and handle situations if any vulnerability is identified in the information system (Yang et al., 2017).
The present research study would also fill the gap which was existed in the previously conducted research studies. However, there were significantly fewer research studies and identified the impact of gamification on IT security training. Still, a significant gap in the literature review, which was identified, conducted research studies in the past.
Research Questions
1. What is the impact of gamification on IT security Training in the IT industry?
2. How can gamification be a practical learning approach to spread awareness about cybersecurity among IT industry employees?
3. What kind of revelations can be apparent if gamification techniques are introduced into the IT industry?
4. How can techniques of gamification be applied to other industries for increasing its popularity?
Research Hypotheses
1. H0: There is no impact of gamification on IT security Training in the IT industry.
H1: There is an impact of gamification on IT security Training in the IT industry.
2. H0: Gamification cannot be a practical learning approach for spreading awareness about cybersecurity among IT employees.
H1: Gamification can be an effective learning approach for spreading awareness about cybersecurity among IT employees.
3. H0: No gamification technique can be applied to other industries to increase their popularity.
H1: There is a gamification technique that can be applied to other industries to increase their popularity.
Cybersecurity awareness can be explained as the people who seem to be aware of several types of cybersecurity threats that can be faced by their networks, systems, and devices (Alomari, Al-Samarraie, & Yousef, 2019). End users are considered the weakest element and the network's primary vulnerability point for allowing several cyberattacks to get inside. Hence, it has been considered highly significant for end-users to stay aware of cybersecurity (Moore, 2019). Several types of methods can be utilized for spreading awareness about cybersecurity, like training sessions can be conducted by using classroom courses, e-learning, presentations, and webinars, etc. It has been observed that spreading awareness about cybersecurity is not considered an easy task ever because there are multiple numbers of training techniques. Still, none of them provided highly effective results (Pattabiraman et al., 2018). Hence, it is considered highly significant to do tailoring in the existing used training practices to provide useful information and increase the interest of participants in cybersecurity (Alotaibi et al., 2016). There is a vast significance in maintaining employee engagement and involvement in the offered training sessions because otherwise, all the applied resources and costs would be useless and wasted. When companies use gamification, they work to make the existing tasks more innovative and fun, like video games. The training's success based on gamification relies on the program's accomplishment without being noticed by using gamification. Security compliance ensures that the company has appropriately taken several security measures to protect the IT infrastructure from several types of attacks, risks, vulnerabilities, and breaches (Hart et al., 2020). The companies must ensure IT security compliance to strengthen and secure the IT departments from several types of attacks, vulnerabilities, and risks. Besides, companies must also provide various training sessions to keep employees' knowledge and skills updated. The current research study's main objective was to evaluate gamification's impact on IT security training related to cybersecurity offered to employees working in any company in the IT industry.
Research Methods and Design(s)
There are several types of research designs that have been most widely used by researchers around the globe. Explanatory, exploratory, experimental, and descriptive research designs are the most commonly used research designs (Creswell, 2017). All the researchers make a selection of the research design for their research study according to the type of data which is needed to do high-quality decision making, the topic of the study, the goals and objectives which are required to be accomplished through the research study, and how to research study would be completed.
For the present research study, it is considered that the use of a descriptive research design would be highly useful because the current research study is related to understanding the impact of gamification techniques on the IT security-related training offered to employees. Various researchers and researchers have already explored the present research study's topic have already conducted different types of literature reviews. Hence, it has been considered that the use of descriptive research design has been considered highly useful, suitable. The appropriate research has been designed to collect high-quality data of which findings would be used to decide the current research study.
Descriptive research design can be explained as the scientific research method, mainly used for observation. It provides a comprehensive description of a single or a set of entities without having any positive or negative impact on the single or set of entities directly or indirectly (Colorafi & Evans, 2016). Hence, it has been considered that the use of descriptive research design would be useful for the current study because there would a survey and an interview conducted to collect primary data.
The research population for a research study can be defined as the set of events, objects, and individuals selected based on their common characteristics and features. The research population has been decided to collect some primary data like to conduct an interview, observation, experiment, or survey of which findings would be used to do the decision-making about the topic of the study. For the present research study, it is decided that the population would be the employees working in different departments of Google so that a variety of opinions, ideas, and suggestions can be taken for ensuring more reliability, accuracy, and preciseness in the collected data.
There is a hugely significant role in selecting suitable and useful sample sizes in all the research studies because it helps in the aggregation of units for conducting a comprehensive analysis of the research study. When a suitable and appropriate research sample has been selected for completing research, it is considered positively supporting for finding accurate, relevant, and precise data that can be further converted into useful information and findings on which decision-making is performed. There are mainly two types of sample methods used by researchers globally, e.g., probability sampling and non-probability sampling.
In the probability sampling method, researchers select respondents to collect primary data randomly and independently. On the other hand, in non-probability sampling, a particular sampling selection pattern is selected and used by the researchers (Taylor et al., 2015). The proposed study aspires to study the relational competence factors in gamification's impact on employees' IT security training. Therefore, the population sample targeted for this study will only include the employees working in different positions belonging to IT companies like Google.
Considering the selected strategy, the researcher will opt for a probability-based random selection of participants to conduct surveys. The sample size can be defined as the smallest unit used in a research study to ensure more credibility, reliability, accuracy, and certainty in the data collected from the primary data collection method. The sample size is the number of respondents selected for collecting preliminary data, like those participants who would be chosen for conducting a survey, interview, etc.
To collect primary data for the current research study, 100 employees were selected for conducting a survey, and six employees were selected for conducting an interview. It was ensured that all company employees should belong to different company departments but connected to IT departments directly or indirectly. Thus, highly reliable, accurate, and useful data can be collected, which can play a significant role in doing highly authentic and realistic decision-making without ambiguity and biasness in the collected data findings.
All the participants for the conducted survey and interview were selected randomly without giving any kind of priority to any employee based on their job position, race, gender, or personal relationships. The questionnaires will be circulated among participants using online media to save time and resources. Similarly, the interviews will be conducted with six people, including managers or top-level employees working in Google but related to the IT department.
Different types of resources were utilized for doing a collection of data like internet connection, and web browser was being used for conducting secondary research and doing data collection from secondary sources. On the other hand, a variety of email addresses were collected of the participants of the survey so that the survey questionnaire can be emailed to them and asking from them to do help in evaluating the results about the impact of gamification in the IT security training related to cybersecurity offered to employees. The survey questionnaire was sent to the collected emails, and their responses were collected and analyzed for effective decision making.
For collecting all the secondary data, an internet connection and computer system were used, on which preliminary research was done by typing several types of phrases and keywords related to the study topic. All the identified material was evaluated and checked under CRAAP to be accurate, reliable, and authentic in the research study. A web browser like Google Chrome was used for doing research on which the search engine Google was utilized. Several databases and journals were accessed and evaluated based on their relevancy with the current research study topic.
The time was utilized to collect the email address and send each survey questionnaire to the collected email addresses for data collection. While on the other hand, there was some cost applied to travel to visit Google's outlet. There was some electricity cost involved in the analysis of collected data from the survey and questionnaire. Besides, a mobile phone was used to record all the voices during the interview so that only authentic and accurate information can be added to the data analysis. A notebook was also used for writing notes and key points identified during the interview, which were considered helpful in interpreting primary data.
For ensuring the validity and reliability of the research, it is considered that the research method selected is appropriate for this thesis, and a reasonable time scale is developing according to the needs and demands of the research. Moreover, it has ensured that the research sample is good enough for ensuring integrity, preciseness, and accuracy. It has assured that all the steps are performed in the thesis. Research validity and reliability apply to the research method and design (Taylor et al., 2015).
The present research study can be validated by using the evaluation of research methods and other types of methods that can be used for doing the collection of data to convert it into information. These different methods can be any one-to-one, face-to-face interview, or collectively surveyed with the selected respondents. Furthermore, it has ensured that the research sample is good enough to ensure the integrity, preciseness, and accuracy of all the collected data. It is ensured that all the steps that have been performed in the thesis are according to the rules of validity and reliability.
Moreover, all the interview questions were related to the objectives of the present research study, which were in the shape of open-ended questions to collect a vast amount of data. Still, the survey questions were in the form of closed-ended questions so that more precise data can be collected. However, all the survey questions were also according to the present research study's objectives instead of two to three inquiries related to respondents' demographic information. Moreover, most of the questions of the survey were according to the Likert scale.
Data collection methods can be defined as the researchers' methods for collecting data of which findings would be used to make the decision making about the topic of the research study. Multiple types of data collection methods have been most widely used by researchers, like case study analysis, experiments, observation, focus group discussion, archival, survey, and interviews. All the data collection methods have been selected according to the study's topic, goals, and objectives, and the course's nature (Yin, 2017).
To complete the current research study, a mixed research method would be used. All the data from two research methods would be collected, e.g., Qualitative Research Method and Quantitative Research Method. All the data collected from the qualitative research method can be from several secondary sources that would be related to the topic of the present study. For this purpose, a web browser like Google Chrome would research the content related to the topic. Several types of keywords would be used for this, like gamification, the impact of gamification, the use of gamification in cybersecurity, the benefits of gamification, etc. All the identified data has been studied and analyzed to select the content and information that is needed to be added and would be useful and helpful for the current research study.
The secondary sources that have been accessed and selected to collect data for the current research study included a literature review of previously conducted studies related to gamification on cybersecurity training. It has provided to employees journal articles, newspapers, websites of companies, blogs, and books available in the university library and the internet. Reports have been published by the companies aiming to use gamification to provide training to their employees and other online published material on the internet. All the data was accessed by using the Google Chrome web browser and the search engine of Google. All the data was collected using several types of databases and journals based on the relevance of the topic. Comment by Jess Schwartz: Please reword this sentence, it needs update for clarity.
All the remaining data for the current research study has been collected from a quantitative research method. A survey and an interview would be conducted from the selected population size. For this purpose, a survey questionnaire and an interview questionnaire would be prepared, distributed when conducting a survey and interview from the chosen population size. The survey questionnaire has been divided into two sections in which all the questions of section one would be related to the demographic information of respondents. On the other hand, the second section of the survey questionnaire would be associated with each present research study's objective. Only relevant and accurate data can be collected to do the effective decision making.
Besides, all the survey questionnaire questions were in the form of closed-ended questions so that highly accurate, precise, and reliable data can be collected to do effective decision-making without ambiguity. All the data collected from the survey would be analyzed, interpreted, and presented using MS Excel so that effective decision making can be done. While on the other hand, all the questions were asked at the time of conducting the interview. It has related to the objectives of the present research study and were formed open-ended questions so that plenty of data associated with the impact of gamification on the IT security training offered to employees can be collected from the selected participants.
Multiple types of assumptions have been faced during working on the current research study. The researcher's most common assumptions while working on the present research study are briefly described below.
1. It was ensured that all the questions asked in the survey and interview would be answered authentically, accurately, independently, honestly, and candidly. High quality, reliable, accurate, and precise primary data can be collected to make high-quality decision-making.
2. It was ensured that all the participants of the conducted survey and interview have selected on the particular criteria, which would be relevant to the current research study's topic either directly or indirectly. Thus, data collected from primary data sources would be useful and highly reliable to make high decision-making.
3. It was ensured that all the participants for the primary data selected might have sincere interest and intentions for participating in the current research study for producing high-quality, practical results. It can be useful and significant for playing a significant role in the social community. It should be ensured that any selected participant does not have any malicious intentions and motives like to get into good books of their superiors, to get any high position or promotion in the company, or to show off in front of others, etc.
4. All the remaining data collected from secondary sources should be collected from only reliable sources. Any kind of inaccurate or outdated information should not be made a part of the present research study or added anywhere in the whole research study.
During the current research study, the researcher faced multiple types of limitations that were needed to be handled smartly, effectively, and appropriately for completing the research study on time and with high accuracy. The main research limitations identified during the working of the present research study are described below with some brief.
1. It was observed that some participants of the conducted survey and interview hesitated in answering the asked question in a very smooth and reliable manner. They were afraid that their answers would be revealed to their superiors or their information would be disclosed in any part of the research study, causing some problems in their professional life.
2. The sampling size that was decided for collecting primary data through interview and survey was small, which contributed to making difficulties in analyzing, interpreting, and presenting data to do high quality of accurate and reliable decision-making.
3. Another major limitation faced while working on the present research study was that the allocated time was not enough because the topic could be studied and evaluated from several perspectives.
4. The finding of accurate, reliable, and authentic information and knowledge regarding the selected topic of the current research study was also a significant limitation faced while working on the present research study because there was a lot of information available from several sources regarding the use of gamification. Still, it was not in the context of cybersecurity.
There were multiple types of delimitations faced while working on the current research study. Some of the main delimitations that have been observed during this research study have been discussed briefly in the following.
1. All the questions added in the survey questionnaire were closed-ended and based on the Likert scale instead of adding any open-ended question or suggestion box, which positively contributed to making more respondents willing to participate in the conducted survey.
2. It has ensured that all the selected respondents of the conducted survey and interview should be the employees working in Google in different IT positions. Only accurate and reliable data can be collected related to the impact of gamification on IT security training.
To complete a research study in a very authentic, ethical, and successful manner, it is highly significant to follow several types of ethical practices so that any problem, challenge, or delay in completing the research study can be avoided. The study can be conducted authentically, accurately, and timely with good quality without putting any kind of physical or psychological harm or problem to any participant of the research study or the authors of the sources from which secondary data has been collected. There were multiple types of ethical concerns the researcher faced during the present research study, which was handled appropriately and effectively.
To complete a research study successfully, researchers must avoid multiple types of physical and psychological limitations and problems of all the participants of primary data collection methods and secondary data collection methods. The following are some of the major ethical concerns that the researcher considered very seriously while working on the present research study.
1. The collection of authentic, accurate, reliable, and original information was one of the significant ethical concerns faced while working on the current research study. Any kind of inaccurate, ambiguous, or wrong information will not be made a part of the research study.
2. It was highly significant to ensure that all the study findings would be subjective to the research study topic. Any kind of personal suggestions, feedback, opinions, and ideas were not part of the course.
3. It was highly important to maintain confidentiality and privacy of all kinds of personal information of authors of secondary sources and participants of the primary data collection method. It was ensured during the whole working of the research study that any personal or confidential information would not be included in any part of the research or disclosed to any third party during data interpretation, analysis, presentation, and decision making.
4. It was ensured that all of the data included in the research study collected from secondary sources should be from publicly available sources so that any kind of credentials like username or password do not need to be added. All the data included blogs, journal articles, literature reviews of already conducted research studies, online published reports, statistics published by companies, books, and other material published material on the internet should be easily accessible anywhere and anytime.
5. All the secondary sources' data were paraphrased or included in double-quotes without making any kind of change in the sentences. Only authentic and accurate information can be included, and plagiarism can also be avoided in any information published by scholars, researchers, and writers.
6. All the survey participants and interview participants would be allowed to answer all the questions independently according to their choice without stress and pressure.
7. All the transcripts of the conducted survey and interview to collect primary data were deleted from all the storage devices and destroyed after running analysis, interpretation, and presentation of all the collected data.
8. All the survey participants and interview participants were asked to sign a consent form to ensure that they participate in the present research study's data collection method by their wish and without pressure from their superiors or the researcher itself.
To complete the present research study effectively, it has been planned that the use of a descriptive research design would be highly useful because of the current research study's nature and how the present research is needed to be accomplished. For this purpose, all the data would be collected from a mixed research method. Two main types of data collection methods would be utilized, like qualitative and quantitative research methods.
It has been considered that all the secondary data for the present research study would be collected from a qualitative research method in which multiple types of secondary sources would be utilized by researching the Google search engine. Online research will help select relevant material found in the study, which is related to the current research study topic. However, all the primary data for the present research study has aimed to be collected from quantitative research method in which a well-structured survey and an interview would be conducted from the selected population size, which would be further analyzed, interpreted, and presented effectively so that highly reliable and accurate decision making can be performed related to the topic of the current research study.
There were several types of research ethical concerns and limitations faced while working on the current research study like respondents were afraid that their names or designations could be revealed in any part of the research study or to their superiors, which can make some negative impression or can put harm to their jobs. The current research study topic was broad enough to be evaluated and explored from several other perspectives and larger sample size. There were multiple types of ethical concerns that were followed very responsibly in the whole research study. Any kind of physical or psychological harm can be prevented from being done to any participant of the conducted survey.
However, in the present research study, multiple types of limitations and assumptions have been faced, which were handled very effectively by following various delimitations to complete effectively and timely without wasting any extra time resources. All the secondary sources that were needed to be used in the research study were selected in the very beginning. Only useful and updated data can be collected and converted into information to effectively complete the current research study.
Summary Comment by Jess Schwartz: This section is missing
References Alomari, I., Al-Samarraie, H., & Yousef, R. (2019). The role of gamification techniques in promoting student learning: A review and synthesis. Journal of Information Technology Education:Research , 395-417. Alotaibi, F., Furnell, S., Stengel, I., & Papadaki, M. (2016). A Review of Using Gaming Technology for Cyber-Security Awareness . International Journal for Information Security Research, 660-666. Baxter, R. J., Kip, H. J., & Wood, D. A. (2016). Applying Basic Gamification Techniques to IT Compliance Training: Evidence from the Lab and Field. Journal of Information Systems, 119-133. Colorafi, K., & Evans, B. (2016). Qualitative descriptive methods in health science research. HERD: Health Environments Research & Design Journal, 16-25. Creswell. (2017). Research design: Qualitative, quantitative, and mixed methods approaches. Sage Publications. Mathoosoothenen, V. N., Sundaram, J. S., Palanichamy, R. A., & Brohi, S. N. (2017). An Integrated Real-Time Simulated Ethical Hacking Toolkit with Interactive Gamification Capabilities and Cyber Security Educational Platform. In Proceedings of the 2017 International Conference on Computer Science, (pp. 199-202). Moore, M. (2019, 9 17). Gamification: A winning strategy for cybersecurity training. Retrieved from https://www.scmagazine.com/home/opinion/executive-insight/gamification-a-winning-strategy-for-cybersecurity-training/ Pattabiraman, A., Srinivasan, S., Swaminathan, K., & Gupta, M. (2018). Fortifying corporate human wall: A Literature review of security awareness and training. In Information Technology Risk Management and Compliance in Modern Organizations, 142-175. Redhead, A., & Saunders, J. (2019). Gamification and Simulation. In Serious Games for Enhancing Law Enforcement Agencies, 83-98. Ruiz-Alba, L., J., Soares, A., Rodríguez-Molina, M. A., & Banoun., A. (2019). Gamification and entrepreneurial intentions. Journal of Small Business and Enterprise Development. Seaborn, K., & Fels, D. I. (2015). Gamification in theory and action. International Journal for Information Security Research. Seaborn, K., & Fels, D. I. (2015). Gamification in theory and action: A survey. International Journal of human-computer studies, 14-31. Taylor, S., Bogdan, R., & DeVault, M. (2015). Introduction to qualitative research methods: A guidebook and resource. John Wiley & Sons. Thornton, D., & Francia, G. (2014). Gamification of information systems and security training: Issues and case studies. Information Security Education Journal, 15-24. Yang, Y., Asaad, Y., & Dwivedi, Y. (2017). Examining the impact of gamification on the intention of engagement and brand attitude in the marketing context. Computers in Human Behavior, 459-469. Yin. (2017). Case study research and applications: Design and methods. Sage Publications.