Need a 10 page APA paper
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 1 of 35
3
2
2
2
3
2
2
1
1
79
8
3
2
49
DOCUMENT SCORE
94 ISSUES FOUND IN THIS TEXT
159 PLAGIARISM
Checking disabled
Contextual Spelling 3 Misspelled Words
Grammar 6 Incorrect Noun Number
Determiner Use (a/an/the/this, etc.)
Faulty Subject-Verb Agreement
Punctuation 5 Punctuation in Compound/Complex Sentences
Comma Misuse within Clauses
Sentence Structure 4 Misplaced Words or Phrases
Faulty Parallelism
Incomplete Sentences
Style 92 Passive Voice Misuse
Intricate Text
Inappropriate Colloquialisms
Wordy Sentences
Vocabulary enhancement 49 Word Choice
of 100
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 2 of 35
The 21st century has come with technological
advancements that have helped organizations flourish and
work faster and more efficiently. There are numerous
changes that the corporate world undergoes, and for an
organization to stay competitive in the market, it must be
able to adapt to the changes that are bound to happen
(Desai, 2016). Organizations must be able to learn quickly
about the business environment. The business principles
change over time, and Information Technology is one of
those fields that a company must take a keen interest in .
The changing technological advancements mostly
include the use of e-commerce, which exposes companies
to a higher risk of cybercrime. According to Al-Kalbani
(2017), there has been a 38% increase in information
technology breaches in a public organization in 2016
compared to 2014. Because of such an increase and the
threat of a further surge. Companies must design and
operate secure electronic systems that they use for the
exchange of information and funds. It is highly
fundamental that the security of information that the
organizations hold to be kept as high as possible.
Companies have noticed the same and have gone on to
adopt security practices that include the adoption of an
information technology security compliance approach to
control the proper use of the information they have (Al-
Kalbani, 2017). Showing that a company has taken the
necessary precautions to protect the information they have
is now considered to be an institutional yardstick (Al-
Kalbani et al., 2017; Safa et al., 2016).
For any sort of security of the information,
companies, and organizations, including governments,
must consider the technical, technological, and non-
technical aspects (Al-Kalbani, 2017). As such, the end
game is to have a set of rules that must be met to ensure
security compliance. In the use of information technology,
security compliance refers to the implementation of
security practices, policies and standards that work best to
protect the information owned or controlled by a particular
organization (Al-Kalbani, 2017; Alfawaz et al., 2010). If a
company complies with information security, it can
1
2
3
1
Preposition at the end of a sentence
2
Noun string
3
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 3 of 35
improve its security mechanisms that help safeguard
information (Siponen et al., 2010). The compliance
approach used to information technology helps satisfy the
trust that the stakeholders have towards the organization
(Al-Kalbani, 2017). Therefore, information technology is
essential in the development of e-government and other
institutions and organizations as well.
As Dimitriadis (2011) describes, information
security is "the preservation of confidentiality, integrity,
and availability of information." There is no way that
information can be preserved if there is no compliance
with the standards that guide its preservation. Over the past
decade, there was the notion that information security was
a technical thing, and the IT managers were the only ones
tasked with the preservation of safety. However, the idea
has been changing to include the non-technical part of the
organization (Desai, 2016). This has led to the creation of
procedures, policies, and awareness programs that help in
security compliance. According to Herath and Rao (2009),
the failure to prevent security breaches in attacks is a clear
sign of a company not complying with the security
policies. Research has ascertained that almost half of the
security breaches that befall an organization emanate from
within the organization (Desai, 2016). This fact places
more emphasis on the role that an organization has in
stopping security breaches through compliance.
According to Kolkowska and Dhillon (2013), there
are two main categories identified concerning information
security approaches. The approaches are the approaches
that make use of sanctions and the behavioral ones. As
such, there are two approaches to security management,
which are the individual level and the managerial level of
understanding (Flores et al., 2014). This means that the
own employees in an organization need proper training and
awareness not to misuse information. The employees need
to understand the consequences of the guilt of breach of
data.
There have been theories that help understand the
compliance of organizations to information security. The
institution theory (DiMaggio & Powell, 1983) widely
provides a better understanding of the pressures that force
4
5
6
Passive voice
4
Passive voice
5
Unclear antecedent
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 4 of 35
an institution to comply. The theory states that
"organizations must secure legitimacy from its stakeholders
by conforming to external expectations" (Appari et al.,
2009). The legitimacy that an organization seeks can be
gained by making strategic responses to the pressures
from external entities (Cavusoglu et al., 2015). It is
paramount to note that the organization's external
influences and the answer define how the organization is
built, run, and how it can be understood and evaluated (Al-
Kalbani et al., 2017).
For an organization to follow security compliance, there
must be proper external pressures that force it. The
influences include normative, mimetic, and coercive
pressures (Cavusoglu, 2015). The coercive pressures are
the ones that force an organization to adopt the regulations
and practices that help in the protection of the security of
information. The demands are mainly from government
laws and regulations (Al-Kalbani et al., 2017). The
normative pressures are those that stem from the
expectations that the community has towards the
organization (Appari et al., 2009). Finally, the mimetic
pressures originate from the company trying to imitate its
peers to gain legitimacy (Safa et al., 2016).
The importance of the pressures to the adoption of security
compliance is key to ensuring that the organizations. Since
many institutions are using Gamification in the training and
awareness of the employees, the mimetic pressures play an
essential role in increasing the compliance levels of other
companies. Bulgurcu (2010) finds out that the
implementation of information security awareness even
helps to increase the belief of employees towards security
awareness. While the government can create rules and
regulations that force organizations to raise information
security awareness, it is down to the organizations to
choose to use Gamification to train the employees.
1.1 Gamification for Security Training
Gamification is the method in which the knowledge and
experience gained from gaming theory and flow theory
have utilized in a non-gaming context. The concept of
Gamification was implemented for the first time during the
Cold War to improve productivity (Alotaibi, Furnell,
7
6
Unclear antecedent
7
Passive voice
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 5 of 35
Stengel, & Papadaki, 2016). Coonradt in 1984 was the
early researcher who applied Gamification in the business
context to motivate employees through clear goals,
frequent feedback provision, gaming features, and personal
choice (Baxter, Kip, & Wood, 2016).
Gamification highly helps companies increase their
employees' engagement level by utilizing several elements
of game designing (Kanat, Siloju, Raghu, & Vinze, 2013).
According to some previously conducted research studies,
it has suggested that the use of goals, storytelling, rewards,
and appreciation are the main aspects of Gamification for
increasing the curiosity, interest, engagement level and
experiences of challenges of users to boost the engagement
level and interest of participants in the offered training
sessions and workshops (Seaborn & Fels, 2015).
The use of the gamification technique is one of the most
preferred training methodologies which helps the
companies to increase innovation, productivity, knowledge,
skills, experiences, and learning procedures of their
employees and participants (Alomari, Al-Samarraie, &
Yousef, 2019). This technique is mainly based on the use
of innovative thoughts and gaming techniques in a non-
entertainment manner, such as improving education and
work skills.
There are vast numbers of benefits offered by Gamification
to its users like it enables employees to increase their
productivity, provides motivation for improving their
engagement and involvement, encourages employees to
become more creative for solving the problems and
innovatively addressing them, provides strength to the
communication procedures (Pattabiraman, Srinivasan,
Swaminathan, & Gupta, 2018).
The use of Gamification highly helps employers and
managers increase employee engagement by introducing
several types of innovative dynamics (Mathoosoothenen,
Sundaram, Palanichamy, & Brohi, 2017). It has assumed
that the companies who utilize the technique of
Gamification in the training sessions offered to their
employees can get more successful in improving the
particular required skills of their employees through the
increased interest and involvement of employees in the
8
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 6 of 35
provided training sessions and workshops (Erenli, 2013).
However, it is also considered a highly useful approach for
transmitting a productive and positive corporate image
(Alomari, Al-Samarraie, & Yousef, 2019).
Using Gamification more effectively, all the things
should be kept simple, engaging, and entertaining to
increase the interest and engagement level of employees.
The success of Gamification relies mainly on employees'
increased involvement, effective gaming techniques, and
methods and motivation (Alotaibi, Furnell, Stengel, &
Papadaki, 2016). The rewards offered are not considered
only pure awards but provide means for inspiring
employees to achieve their potential. There are vast
numbers of organizations that have to utilize gamification
techniques like Google, Starbucks, and Dominos, etc.
When companies use Gamification, they work to
make the existing tasks more innovative and fun, like the
use of video games. The advancement in information
technology has highly contributed to increasing
cybercrimes and terrorism that can put strong negative
impact not only on the reputation of the company but also
on the data and information stored in the servers of the
company of their employees, customers, and the
organization itself (Baxter, Kip, & Wood, 2016). The
increased numbers of attacks, threats, risks, and
vulnerabilities demand the IT companies become more
innovative, productive, and reliable (Gonzalez, Llamas, &
Ordaz, 2017).
For this purpose, companies have needed to provide
training sessions and workshops to improve their
employees' skills and knowledge. To identify and tackle the
various attacks, threats, risks, and vulnerabilities,
employees should know about IT security so that they can
protect their privacy and data from intruders (Erenli, 2013).
Employees should also be able to think from the
perspective of intruders and act accordingly.
To identify and address the cyberattacks effectively,
quickly, and without any significant loss in terms of
finance, customers, and reputation, the employees should
have updated knowledge as advancements in technology
are taking place at a fast rate (Seaborn & Fels, 2015).
9
8
Passive voice
9
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 7 of 35
Several types of cybercrimes can be occurred and can be
proved highly harmful. In 2018, the UK, 79% of
companies were posed with the threat of cyberattacks and
had to face the consequences of problems that occurred
(Alomari, Al-Samarraie, & Yousef, 2019).
Most people, including the employees of any organization,
do not show interest in attending workshops related to any
topic as the workshops play a significant role in enhancing
the knowledge of its attendees to improve their existing
experience and skills about the security of IT infrastructure
(Luh, Temper, Tjoa, Schrittwieser, & Janicke, 2020).
However, a significant problem is faced by a lack of
interest and involvement in the offered training and
workshops, which can be solved using gamification
techniques (Hart, Margheri, Paci, & Sassone, 2020).
Besides, the usage of Gamification for increasing
the involvement and engagement level of employees has
considered to be very cost-friendly as it can provide a
considerable amount of benefits to its users and can save
them from major problems like in case of having lack of
involvement and engagement level of employees in the
offered sessions, all the resources which were utilized by
the companies like cost, time, place, etc. would get wasted
and of no use (Seaborn & Fels, 2015).
Gamification works on the desire of human beings
to get the win, successful, and achieve something. It allows
employers to offer several types of rewards like badges,
points, leader boards, and the ability to do trading to get a
particular kind of prize for deriving high quality of
behavior from employees to get engaged in the training
sessions (Thornton & Francia, 2014). However, it is also
rooted in science, as wining always creates dopamine in
human beings' minds. They want to get reached to the next
level and be placed on the top of the leader board by doing
whatever they can to feel good and have a feeling of pride
(Alotaibi, Furnell, Stengel, & Papadaki, 2016).
Besides, there is also the considerable significance of the
rules needed to follow for staying in line and to get
guided in the decision making. The companies who get
successful in implementing and establishing the right
standards for the Information Technology Security
10
11
Passive voice
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 8 of 35
awareness training sessions and programs can have more
opportunities and chances of extending their programs for
having long term benefits (Gonzalez, Llamas, & Ordaz,
2017). All the specified rules, regulations, objectives and
goals of the training are needed to be clear and
straightforward for getting modified and adjusted
according to the changing circumstances and situations
(Adams & Makramalla, 2015).
Organizations should not move towards the use of
Gamification because everyone is using it, and it sounds to
be very trending and good. It should be implemented
when needed and with a particular purpose (Seaborn &
Fels, 2015). All the programs which contain Gamification
should have some unique value, and all the participants
should be felt to be very special and interested in learning
about cybersecurity for securing the IT departments of the
companies by having a feeling of winning something
(Alomari, Al-Samarraie, & Yousef, 2019).
All the contents of Gamification in the training
sessions are needed to be incorporated in a very
transparent manner for obtaining a high level of benefits as
it can be proved to be very useful and practical for
improving the quality of training sessions and achieving a
high level of results (Alotaibi, Furnell, Stengel, &
Papadaki, 2016). The success of the training based on
Gamification relies on the program's accomplishment
without being noticed by using Gamification (Gonzalez,
Llamas, & Ordaz, 2017).
It has also noticed that the things that work well for one
organization are not compulsory and would be sufficient
for the other companies (Seaborn & Fels, 2015). Each
company seems to have its particular unique organizational
culture and training programs designing methods because
of having unique traits and knowledge (Alomari, Al-
Samarraie, & Yousef, 2019). In each training session,
human factors are considered to be the weakest element
for IT security as they can make mistakes, and they are also
the ones who can make extraordinary efforts to secure the
system to a great extent from vulnerabilities, risks, and
attacks (Chen, 2015).
There is a considerable significance of information security
12
13
14
15
16
10
Passive voice
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 9 of 35
compliance for improving the quality of operations and
services which are being offered to customers. When
customers feel that their data is not protected and secured
by their company, they hesitate to provide their confidential
and personal information (Adams & Makramalla, 2015).
There are many cases in which several numbers of
organizations have to face a significant loss in terms of
customers and finance because of loss of information and
data due to several types of vulnerabilities, breaches, and
attacks (Alomari, Al-Samarraie, & Yousef, 2019). For
example, in 2013, Adobe has to compromise the data of
153 million users, which caused the company to face a $1.1
million legal fee and $1 million to its customers for solving
their problems (Swinhoe, 2020).
Also, in 2014, eBay has to compromise 145 million users'
data, which caused the company to pay hefty fines and
some corresponding amount to their customers for
addressing the impact which has been faced by them
financially (Battaglino, 2019). There are hundreds of
examples of smaller, medium and large scale organization
which are offering their services by collecting vast types of
personal and confidential data of their customers and
employees and those companies have to face millions of
dollars of loss not only in terms of money but also in their
customers and reputation (Alotaibi, Furnell, Stengel, &
Papadaki, 2016). If these organizations have put a strong
focus on the improvement of their IT infrastructure and
implemented robust security compliance, they could have
saved themselves from these significant losses.
Security compliance ensures that several security measures
have been appropriately taken by the company to protect
the IT infrastructure from several types of attacks, risks,
vulnerabilities, and breaches. Several IT security regulatory
compliance numbers can be followed by organizations
(Armstrong & Landers, 2017). This compliance can be
effectively implemented if all the relevant employees
seem to be aware of these practices. They have relevant
skills and updated knowledge that is possible to provide to
employees who seem to have problems in these areas
through the training sessions.
The offered training sessions can be improved by using
17
18
19
20
11
Faulty parallelism
12
Passive voice
13
Passive voice
14
Passive voice
15
Passive voice
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 10 of 35
the practice of Gamification, which allows employees to
take significant interest and involvement in the provided
training sessions. These training sessions can help
employees understand updated and highly advanced
methods to address these vulnerabilities, attacks, and
breaches (Baxter, Kip, & Wood, 2016). Employees can be
offered advanced knowledge about several types of IT
security regulatory compliance like FISMA, HIPPA,
SURBANCE OXELY ACT, PCI DSS, etc. All these acts
work effectively with the collaboration of IT security
agencies and the government to secure the confidential and
personal data of customers and employees.
FISMA is a law that was passed in 2002 by the United
States Federal, which indicated that the federal agencies
should do development, documentation, and
implementation of adequate information security and
protection programs. It is made for the improvement of
the management of e-government. It is considered to be
the most significant rules, followed by federal data security
standards and guidelines (Gikas, 2010). The primary
purpose of it is the reduction of security risks for public
information and data.
HIPPA (Health Insurance Portability and Accountability
Act) of 1996 was designed to contain comprehensive
information about protected health privacy and security.
However, confidentiality and security cannot be considered
the same but always stays together. The privacy rules
mainly focus on the individual's rights for controlling their
personal information (Edemekong & Haydel., 2019).
According to PHI (Protected Health Information), it is
stated that any kind of personal data should not be used
or disclosed to any other person without their consent.
SURBANCE Oxley was passed in 2002 by the US
Congress for providing help to do protection of investors
from several types of fraudulent activities related to
finance. It is also called a SOX Act of 2002 and the
Corporate Responsibility Act because it brought several
substantial reforms about the existing security regulations
and introduced new lawbreakers and penalties. The act
came in front because of financial scandals that occurred in
2000, like Enron Corporation, World Com, and Tyco
21
22
23
24
25
26
16
Passive voice
17
Passive voice
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 11 of 35
International Plc.
PCI DSS is a set of widely accepted policies that are used
for optimizing the protection of debit, credit, and cash card
transactions and also for the protection of cardholders for
avoiding any kind of misuse of personal and confidential
data (Ataya, 2010). Both were joined in 2004 by using
four significant companies of credit cards: Visa, Discover,
Master Card, and American Express. All of these acts work
effectively with the collaboration of IT security agencies
and the government to secure the confidential and personal
data of customers and employees.
The companies which do not follow the guidelines,
practices, standards, and policies defined by these agencies
and government have to face massive amounts of penalties,
punishments, and fines, which can cause them to suffer a
major loss in terms of finances and customers. These
defined standards help organizations to protect credit card
information, email address, bank details, etc. (Chen, 2015)
For this purpose, it is suggested that organizations should
offer time to time frequent training sessions to their
employees so that they can get updated knowledge, skills
and get aware of best practices that can be utilized by them
for strengthening their IT infrastructure and ensuring IT
security compliance (Gonzalez, Llamas, & Ordaz, 2017).
It is suggested that organizations should keep offering
short training in their meeting sessions for understanding
the effectiveness of existing knowledge of their employees
and every three months employees should be provided with
some short workshop session for increasing awareness and
training sessions should be provided to employees
annually or whenever a new employee joins the company
for making him/her compatible with the requirements of
the company (Gonzalez, Llamas, & Ordaz, 2017).
There are many large-scale organizations which have also
been become a victim of these vulnerabilities, breaches,
and attacks because of lack of implementation of security
compliance. For example, in 2014, there was an attack
made on Yahoo which revealed that the companies having
the latest technologies could also become vulnerable to
these problems and the attacks got successful in stealing
the records of more than 500 million accounts
27
28
29
30
31
18
Passive voice
19
Passive voice
20
Passive voice
21
Passive voice
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 12 of 35
(Pattabiraman, Srinivasan, Swaminathan, & Gupta, 2018).
Besides, there was also a significant attack made on the
Marriott Hotels in which the data of more than 500 million
customers was stolen .
Hence, if these companies had implemented strong IT
security regulatory compliance and followed the practices
and standards specified by the country's IT security
agencies and government, they could have saved their
millions of dollars along with their reputation and numbers
of customers (Thornton & Francia, 2014). The
organizations can enhance their data management
capabilities, improve the status, and market position of the
company. Also, these regulatory compliance helps
organizations to promote operational benefits (Gonzalez,
Llamas, & Ordaz, 2017).
2 State of flow in Gamification for Effective Security
Training
The theory of flow is considered useful for explaining the
procedure in which the use of Gamification can be highly
valuable to improve the learning capabilities and skills of
individuals. The main reason behind the use of the theory
of flow is that most of the games have been designed in
such a manner that puts a strong focus on maintaining a
balance among the skills and challenges of the learners.
However, the individuals who play video games are
considered highly efficient as they can learn and find the
easiest ways to reach the state of flow to learning
something (Luh, Temper, Tjoa, Schrittwieser, & Janicke,
2020). When an employee feels exhausted and bored with
the training sessions, the practice of Gamification helps
them regain their interest and flow in the offered training
session.
Gamification is considered highly useful for allowing
individuals to keep working and taking interests in the
offered tasks in a flow. A flow helps individuals to work on
a particular job in a stream like from the beginner's levels
to medium level, and when they get right in all those
activities, they are moved to the expert level (Gonzalez,
Llamas, & Ordaz, 2017). In the same way, employees are
provided with training sessions based on the beginning
level knowledge to medium and then expert varying in the
32
33
34
35
22
Passive voice 23
Passive voice
24
Passive voice
25
Passive voice
26
Passive voice
27
Passive voice
28
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 13 of 35
offered activities and training. It helps individuals to
develop relevant skills, thinking capabilities, and learning
attitudes based on their experience (Erenli, 2013).
However, there is a significant role played by intrinsic
motivation in the flow theory. The intrinsic motivation
usually occurs whenever an individual starts participating
in the behavior that seems to be personally rewarding not
only because of the pressure that occurred by external
assets but also internally by the person (Baxter, Kip, &
Wood, 2016). Intrinsic motivation occurs when individuals
want to explore or learn something new that is not done by
them before and become more curious about the practical
experience of those things (Wolfenden, 2019).
There are several numbers of research studies that have
been conducted to understand the effectiveness of the
theory of flow. Still, the researchers do very little work on
the evaluation of the efficacy of flow theory on
Gamification and how they can be useful to improve the
capabilities of employees who are working (Pattabiraman,
Srinivasan, Swaminathan, & Gupta, 2018). The flow theory
is considered highly helpful in enhancing the efficiency of
the activities and tasks performed by using Gamification.
According to Cakmak et al. (2015), flow theory addresses
how a person engages in an activity that helps improve his
or her cognitive skills. The engagement involves the unique
feeling of a sense of control, being entirely concentrated on
the operation performed, enjoying the activity, and having
the necessary harmony between the skills and the task
completed (Cakmak et al., 2015). Csikszentmihalyi (1990)
argues that people can achieve happiness by only
controlling how they feel in the inner being. An individual
can control his life and live the most enjoyable moments of
his life by directing his mind to realistic goals and
challenges. Therefore, a person who entirely puts his or her
focus on the work they do will live the flow experience and
will have control over the actions they perform.
According to Csikszentmihalyi (1990), the flow experience
is interwoven with positive emotions, intrinsic
motivation, high concentration, and a sense of control. It is
important to note that individuals mainly experience
intrinsic motivation whenever they are doing activities that
36
37
38
39
Passive voice
29
Overused word: major
30
Passive voice
31
Repetitive word: provided
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 14 of 35
they are interested in . This intrinsic motivation is a vital
feature of the flow experience. Therefore, intrinsic
motivation is easily achieved if a person performs an
activity out of his or her own free will (Cakmak et al.,
2015). There are features of flow experience that are
important in determining the flow experience of a person.
Eight principles are A challenge activity that requires
skills, the merging of action and awareness, clear goals,
direct feedback, concentration on the task at hand, the
sense of control, the loss of self-consciousness, and the
transformation of time (Chen, 2015; Cakmak et al., 2015).
The flow is primarily based on activities and argues that
healthy persons enjoy their experience during the business
without even realizing it (Cakmak et al., 2015). By
accumulating the appropriate events to the purpose of their
life, a person can achieve the happiness they wish with a
sense of control over the activity they perform. Flow theory
has been used before in many fields, including sports,
positive psychology, marriage, job performance, and
distance education (Cakmak et al., 2015). In playing online
games, the creators of the games have mastered the art of
ensuring that they achieve the flow experience when
playing. This way, video games have infiltrated our daily
lives so that every person, young and grown-up, represents
video game (Chen, 2015). The ability for game makers to
ensure that gamers achieve flow experience is by making
sure that there is a balance between the challenges that the
game provides and the skills of the person playing (Chen,
2015).
For ensuring IT security compliance, companies are
needed to have updated knowledge and skills, which can
be achieved by offering several types of training sessions
to their workforce. When the employee is asked to get
training sessions, they feel boredom and lack of interest
which can be improved and increased by following the
practice of Gamification in which several types of games
and rewards can be offered to employees to learn the
concepts more effectively and maintaining a balance
among the interest of employees and their leaning
capabilities (Baxter, Kip, & Wood, 2016).
Human beings are the key asset for creating most of the
40
41
42
43
44
32
Passive voice
33
Passive voice
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 15 of 35
vulnerabilities, breaches, and attacks, along with
addressing them. Hence, their training is considered highly
influential in any organization because they are considered
highly responsible for handling data and IT infrastructure
(Ruiz-Alba, L., Soares, Rodríguez-Molina, & Banoun.,
2019). If employees were offered updated knowledge,
practices, and experiences, they would be able to make
high-quality decision-making to address the problem more
effectively, rapidly, and smartly without getting significant
issues for the company.
Gamification is a relatively new approach that takes
advantage of the video gaming industry to help in the
training and awareness of information security. The era
now is full of online forms, which include transfer and
storage of information. The internet use to store and
transfer information poses a risk of people hacking to get
the information they illegally. In some instances, the
leakage of information may be unintentional, as Desai
(2016) states, almost half of the security breaches that
occur an organization emanate from within the
organization. Most of the violations are unintentional and
are because the users are not aware of the simple ways they
can leak information. Therefore, the gamification process
uses gaming principles to make training on cybersecurity
engaging, entertaining, and informative. This way, the
employees get to learn the techniques of stopping leakages,
following rules. In a nutshell, following regulations and
preventing leakages leads to security compliance.
Information security compliance by the employees means
that the whole organization complies and therefore
heightened security. There is a strong relationship between
the theory of flow, IT security regulatory compliance, and
Gamification because organizations are needed to
strengthen their IT infrastructure by implementing IT
security Compliance (Pattabiraman, Srinivasan,
Swaminathan, & Gupta, 2018).
Information security is a top priority for any company an
organization. To increase the security of information, the
training of employees is essential. If the employees are
trained regularly, and through the best possible formats,
their awareness will be heightened . Increased awareness
45
46
47
34
Passive voice
35
Passive voice
36
[capabilities ],
37
Repetitive word: intrinsic
38
Passive voice
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 16 of 35
of the threats related to information security by the
employees, means that they will not be caught flat-footed
in case of an attack. The increased use of Gamification
increases the willingness of the employees to learn about
information security. The increase in awareness means that
they will be much more willing to be involved in securing
the information of the organization. The use of
Gamification increases the relationship between
information security compliance and the security of data.
There is a strong impact of Gamification in IT security
training. Gamification is a practice of following several
types of gaming activities in return for some rewards,
acknowledgments, and recognition for increasing the
involvement and interests of participants. There is a
considerable contribution of Gamification in increasing the
engagement level, and the importance of employees in the
offered training sessions regarding IT security. The
advancement in information technology has highly
contributed to growing several types of cybercrimes and
terrorism, which also increased the significance of IT
security training sessions offered to employees for
improving their existing knowledge and experiences.
3 Research Question and Hypothesis
3.1 Research Question
The Impact of Gamification in Security Training for User
Security Compliance is moderated by the flow enabled
by the game-based training.
3.2 Hypothesis
H1: Game-based training leads to higher-level user security
compliance
H2: A high state of flow in game-based security training
will lead to higher user security compliance.
H3: A low state of flow in game-based security training
will lead to lower user security compliance.
3.3 Justification for hypothesis
H1:
Silicon and Lowry (2020) conducted a DSR project, which
is the Design science research, to improve the problems of
the users of organizations. The issues which were
discussed in this article included unsuccessful prevention
of phishing, ineffective security compliance, and sparse
48
49
50
39
Passive voice
40
Preposition at the end of a sentence
41
Passive voice
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 17 of 35
learning of the security training. In this article, A game-
based security training system was developed, which
focused on two elements: (1) increasing the intrinsic
motivation of the employees so that they can develop
efficient user security systems (2) improving the learning
of these security training and competency.
The vital hypothetical affiliation of this article proposes a
speculative kernel theory from the adoption model of the
hedonic-system of motivation that can be used to assess
the users and employees regarding their motivation level
and their coping abilities regarding security and
sustainability of the user's security. Four hundred twenty
members participated in the six-month field study, which
was discussed in this article, shows that fulfilling the
coping needs and motivation of the user can make a
significant positive difference in the user security
compliance through efficient and effective gamified
training. A design science research project empirically and
theoretically demonstrates that a carefully selected design
with information technology artifacts that are gamified can
improve the framework of the safety of the organization as
well as ensure user security compliance. To be specific, this
article shows through a long-term field study that the
game-based security training or the incorporation of
Gamification can be used to develop a framework that is
less of a hindrance to the regular work schedules of the
employees, gives the intrinsic motivation to the employees
to comply and learn the security training efficiently, and
provides the actual efficacy which is necessary for the
employees actually to meet and learn. In the same way, this
article demonstrates the improvement in the anti-phishing
responses which are generated due to the hiring of third-
parties. These third parties test the employees and phish
them as natural experiments. Furthermore, this article
presents a new experimental demonstration of the
reasonable significance of the "appropriate challenge" in
this unique situation. This article illustrates that a
combination of design science research, careful contextual
implementation of kernel theory, and long-term analysis in
an experimental field setting is a promising way to
successfully implement game-based training in the
51
52
53
54
42
Passive voice 43
Passive voice
44
Passive voice
45
Passive voice
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 18 of 35
organizations which if adequately learned by the
employees, can lead to an efficient user security
compliance (Lowry, 2020).
This article supports our hypothesis. The design science
research techniques and hedonic-motivation system, if
correctly applied and efficiently implemented, can lead to
higher-level user security compliance. The design science
research and the hedonic-motivation systems are the basics
of the gamification security literature. Hence, (Lowry,
2020) by their long-term field study experiment in which
they incorporated the core kernel theory, the hedonic-
motivation system, and the design science research, proved
that game-based training leads to higher-level user security
compliance.
Baxter et al. (2016) gave evidence from the lab and field
and applied the basic game-based techniques to
information technology compliance training. This article
addressed the main problems of these security training.
Organizations rely on internal controls to secure the
integrity and security of the data of their users. Data
privacy training and information technology security are
the primary controls to protect the organization's data.
Often, it is seen that employees do not like such kinds of
training, however, which may indicate a lack of internal
control, a lack of attention, thus leading to a lack of
success. To improve the experience of these training ,
organizations adhere to game-based techniques in the
training modules of the employees, which is known as
Gamification. In this article, an information technology
field study was conducted for security training, and a lab
study was done for the data privacy settings. The field
study was conducted on bank employees. This article
examined and compared whether a non-traditional game-
based training module increased the satisfaction and
learning of the employees as compared to the traditional
non-game-based training techniques. The article
discovered that Gamification or the incorporation of the
game-based training system brings higher levels of
satisfaction in the field and lab and thus leads to higher
user security compliance. Still, so far, there has not been a
significant increase in learning. Plus, these learning
55
56
57
58
59
60
46
Passive voice
47
Passive voice
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 19 of 35
upgrades were rare and quite small, like 1 percent to 3
percent. Furthermore, this article concluded that gamers,
i.e., individuals who are interested in gaming individually
learned more about game-based training than non-gamers,
even though the gamers had a less satisfaction level from
the gamification training (Baxter, Kip, & Wood, 2016).
This article supports our hypothesis that game-based
techniques can lead to a higher level of user security
compliance but further addresses the need for
implementing some modifications to these gamified
training. First of all, the training should not be this much
long that can hinder the coping and learning abilities of the
users. Secondly, these game-based training should be given
in simple language rather than the IT language, so that a
gamer or a non-gamer; everyone can understand the
training quickly. Thirdly, the gamified training should be
conducted in a calculated period when the employees can
spare time for these training easily and not feel hectic after
the course. All of these modifications that the article
addresses, including keeping up with the motivation of the
user, filling the gap in the learning of gamers and non-
gamers, and keeping the gamified training course short and
comprehensive are the efficient way of implementing the
gamified trainings . Hence, (Baxter, Kip, & Wood, 2016)
findings support our hypothesis that if correctly
implemented, game-based training can lead to higher levels
of user security compliance.
H2:
Yoo et al. (2018) explored the influence of psychological
ownership and flow on training, security education,
security compliance, and awareness effectiveness. The
purpose of this article and the problems that this article
addressed include the investigation of the psychological
ownership and the effects of higher flow on SETA, which
is the security education, awareness, and training, security
compliance intention, effectiveness, and self-efficacy. The
experience of flow at security education, awareness , and
training has been introduced as a pivotal precursor to the
expectation of security compliance intention, effectiveness,
and self-efficacy. To achieve these goals , this article
proposes a hypothesis structure and break down the survey
61
62
63
64
65
66
67
48
Passive voice
49
Repetitive word: flow
50
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 20 of 35
information to test the hypotheses. The components of flow
in security education, awareness, and training are
extended for this study, and the elements like feedback,
challenge, immersion, autonomy, and social interactions
are included .
The results of this article represent that the flow at security
education, awareness, and training encounters significant
associations with the psychological ownership and
effectiveness of security education, awareness , and
training, which thus positively and directly influence the
intention of security compliance. Some managerial
implications and theoretical framework are also
discussed in this article. This article proposes a
hypothesis and proves it with the help of field surveys that
an immersive flow in the security education, awareness,
and training leads to the user security compliance intention.
The hypothesis model or the conceptual model of this
article states that factors like feedback, challenge,
autonomy, social interaction, immersion, feeling in control,
an intrinsic interest of the employees in the activity,
focused attention of the user on the activity and a feeling
of curiosity in the user regarding the activity leads to an
immersive flow. This immersive flow gives rise to
psychological ownership and security education,
awareness, and training simultaneously. Security education,
awareness , and training lead to self-efficacy. This self-
efficacy and psychological ownership combined lead to
user security compliance intention.
The findings of the investigations of this article make many
contributions to information security literature. One
significant contribution includes that the investigation
found that the flow in security education, awareness, and
training has a positive impact on data security in an
association. The investigation of this article found that an
immersive increase in the flow of security education,
awareness, and training leads to user security compliance
intention. There is a remarkable link between the user
security compliance intention and the immersive flow at
security education awareness and training. This
investigation also showed that the employees who have
high SETA effectiveness are more likely to comply and
68
69
70
71
72
73
74
75
76
Passive voice
51
Passive voice
52
Passive voice
53
Passive voice
54
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 21 of 35
agree with the security policies of the organization (Chul
Woo Yoo, 2018).
From all the investigations and results of this article
mentioned above, it is evident that the investigations of
this article are in support of our hypothesis. Our hypothesis
states that a higher flow in the game-based training leads to
higher user security compliance, which was proved in the
article provided by (Chul Woo Yoo, 2018). According to
(Chul Woo Yoo, 2018), the link between the high flow or
immersive flow and user security compliance intention is
complex as a higher user security compliance is
achieved after the implementation of many steps. But this
is a direct link, and through psychological ownership and
self-efficacy, higher flow in the game-based training leads
to a higher level of user security compliance intention in
the employees.
Nakamura and Csikszentmihalyi (2009) researched the
flow theory. They stated in their article, flow is the
complete immersion of an individual in a task or an
activity, and this flow leads to positive psychology, which
in other words can be described as the psychological
ownership. This psychological ownership, as illustrated by
(Chul Woo Yoo, 2018), leads to higher user security
compliance intention (Jeanne Nakamura, 2009).
Brühlmann (2013) wrote an article on game-based training
methods from the perspective of flow and self-
determination. This article stated that in the collaboration
of humans and computers, the game-based training or the
gamification trend is a piece of the initiative of primary
interest, ranging from facilitating all-encompassing
procedures to the user experience approach. This article
addresses Gamification as the use of game components in a
non-game setting. It is gradually and increasingly used in
learning, sports, health care, sustainability, crowdsourcing.
Higher expectations are placed regarding the positive
impacts of Gamification as consumer loyalty is low in
today's internet.
This article discusses the Gamification from the viewpoint
of the motivational theories. Extensive research on the
reward strategies and investigations in the field of
computer games makes the self-efficacy and self-
77
78
79
80
81
82
83
Passive voice
55
Passive voice
56
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 22 of 35
determination theory a possible starting point. Similarly,
the idea of flow has features when it comes to designing
usability and optimal user security compliance. Following
the self-determination theory, the potential effects of
individual, situational, and logical variables are examined
in this study. The article addresses that intrinsic motivation
in a task leads to higher flow, and a higher flow leads to
higher self-determination. This higher self-determination
state leads to better user security compliance. The factors
mentioned in this article, which contribute towards a higher
state of flow, include challenge-skill base, action-
awareness merging, clear goals, and concentration on hand
at task. The results of the article's investigation conclude
that flow has a practical approach. Aspects like the sense of
control, action-awareness, and concentration lead to higher
flow and ultimately increases the usability and user
security compliance (Florian Brühlmann. E Mekler, 2013).
This article is also in support of our hypothesis. It is
proved by the investigations of this article that clear
goals, feedback, sense of control if incorporated in the
gamification system can lead to higher flow. This higher
flow can cause higher user security compliance intention,
as the hypothesis of this paper proposes.
H3:
Hamari and Koivisto (2014) measured the flow in
Gamification by the dispositional flow scale in their article.
This paper assesses the flow of the game-based training
and studies the psychological properties of the
Dispositional Flow Scale-2. This paper uses information
collected from clients of an exercise of Gamification (N =
200). The psychometric examination and of this article
suggested that the flow components are based on the
related divisions of the flow, which are similarly gradually
seen in relation to game-based training. These include a
balance of challenge and skill, feedback, clear goals,
control, and autotelic experience. The article suggests that
the possible outcomes of a lower level of flow can be loss
of sense of time, loss of concentration, merging of action
and awareness, and loss of self-consciousness.
The article reveals from the psychometric analysis that the
flow in the context of game-based trainings should be
84
85
86
87
88
Dangling modifier
57
Passive voice 58
Passive voice 59
Passive voice
60
Repetitive word: article
61
Repetitive word: gamers
62
Repetitive word: training
63
Repetitive word: training
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 23 of 35
seen as a division between different settings of the
conditions to reach the complete flow state and its
consequences which result from achieving the whole flow
state rather than fully observing the nine dimensions
including concentration, time, autotelic experience, clear
goals, feedback, challenge-skill balance, loss of self-
consciousness, control, and merging action-awareness, as a
total view of the flow (Juho hamari , 2014).
The investigations of this article support the third
hypothesis of this paper that a lower level of flow leads to
lower user security compliance. The article proves that the
nine dimensions of flow are nine separate things, and lower
efficacy of any of the nine aspects lead to a lower level of
learning, motivation, self-determination, and self-efficacy.
And as (Chul Woo Yoo, 2018) illustrates that self-efficacy
is directly linked with the user security compliance
intention; it is proven that a lower state of flow in the
game-based training leads to a lower level of user security
compliance.
Chan and Ahern (1999) suggested that modifying the
components of the flow theory can lead to the likelihood of
an increase or decrease in the learning experiences of the
students. The article states that while some scientists
suggest the activity content to increase the learning
experiences, for example, the flow experience, challenge,
and clear goals, others estimate that the flow upgrades
through interactive presentation and vividness. This article
explores the relationship of the presentation , the activity
content, and the flow experience in the teaching process.
The results suggest that the activity content factors like
inducing clear goals and inducing flow experience have a
significant effect on the motivational levels of the students.
However, the introduction is a double-edged blade. The
presentations of Hypermedia and the induction of flow can
motivate the students if they are appropriately used . At
this point, when the hypermedia presentations are new, and
the flow components are new to the students, elaborate
introductions can take a distracting turn. Therefore, when
the difficulties are severe and the students are new to the
flow understanding, the components of Hypermedia should
be used sparingly to start the learning experience. As the
89
90
91
92
93
94
95
96
64
[ ]
65
Repetitive word: awareness 66
Passive voice
67
Dangling modifier
68
Passive voice
69
Passive voice
70
Repetitive word: awareness
trainings training→
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 24 of 35
exercise progresses, and students are capable of fully
understanding the flow components, the learning
experience will increase (Tom S. Chan, 1999).
This article indirectly supports our hypothesis. The
article states an indirect link of flow with user security
compliance. The article proves a direct link of flow with
learning and motivation. And learning and motivation are
indirectly related to the self-efficacy of the employees,
which further leads to user security compliance. Now, this
article by YY illustrates that lower induction of flow
experiences complicated hypermedia presentations lead to
lower learning and motivation experiences, and this
hypothesis ultimately leads to the theory that a small state
of flow in game-based security training will lead to lower
user security compliance.
García-Jurado et al. (2018) evaluated the role of flow and
Gamification in the e-commerce industry. The article
works on three principled goals. In the first place, it looks
at the effects of game-based training on behavioral
intention towards an e-commerce website. Second, this
paper analyzes the impacts of the state of the flow on the
usage of e-commerce sites. Ultimately, the investigation
intends to identify and separate the contradictions between
millennia and Generation X. In this study, data was
collected from Amazon users. Gamification in
Millennials has positive and critical roundabout impacts on
conduct goals through the stream state. On account of the
Generation X, it has been identified that stream
meddles in its impression of usability. The social aim of
utilizing the Web page is straightforwardly related to the
buy expectation. Organizations should offer a pleasant
interface to Millennials and a situation simpler to use to
Generation X, for Gamification to be effective. The
incorporation of game-based training in Millennials has
positive and critical roundabout impacts on conducting and
achieving the goal through the complete flow state. On
account of Generation X, it has been identified that flow
meddles in its impression of usability. The social aim of
utilizing the Web page is straightforwardly related to user
security. Organizations should offer a pleasant interface to
Millennials and a situation simpler to use to the Generation
97
98
99 100
101
71
Passive voice
72
Repetitive word: activity 73
Repetitive word: activity
74
Repetitive word: awareness
75
Repetitive word: investigation
76
Repetitive word: investigation
77
Repetitive word: investigations
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 25 of 35
X, for Gamification to be useful as dull interfaces do not
help to achieve any of the dimensions of the flow like less
time for the consumers to buy the products. These flat
interfaces lead to a lower state of flow , and the lower
state of flow leads to less user security of purchasing the
goods.
This article illustrates that the lower the flow, the lower is
the enjoyment of the user. And the fun is quite essential for
the users to revisit the page. Millennials who don't
encounter a stream, Gamification can have negative results
on the behavior intention of those users. On the off chance
that they are most certainly not getting a charge out of the
Web or suitably focused, a symptom of lower flow, the
game-based training can bore or distract them, which
makes a feeling of dismissal. On account of Generation X,
the Gamification additionally doesn't influence the
expectation to utilize, and, similarly, as with the
Millennials, a higher flow state is required to create
constructive outcomes. This article supports the hypothesis
and illustrates that with a lower flow, the Gamification can
produce no significant results (Alejandro García-Jurado,
2018).
3.4 Motivation for hypothesis
H1: Game-based training leads to higher-level user security
compliance.
For the first hypotheses, which states that the Gamification
or the incorporation of the game-based training techniques
in the workplaces leads to an increased level of user
security compliance, two articles were chosen in support
of this hypothesis. The two articles supporting the
hypothesis are (Baxter, Kip, & Wood, 2016) and (Lowry
2020). The hypothesis of this paper states that if the
game-based techniques are incorporated in the training
of the employees, it can inevitably lead to a higher
confirmation and assurance of the security of the users. The
elements of gameplay like competition, rules of play, point-
scoring are the essential elements of applying game-based
techniques in a non-game context. If asked to a training
session, these elements can motivate the employees to
work harder and focus on their duties while competing with
other employees, scoring points, and proving that they are
102
103
104
105
106
107
108
78
Passive voice
79
Overused word: complex 80
Passive voice
81
Passive voice
82
Passive voice
83
Passive voice
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 26 of 35
capable of what their job requirement is. The competition
with other employees in the training sessions lead to an
appropriate challenge phase. This appropriate challenge
then leads to employees' motivation to do better for the
organization and the users.
Now it is understandable that implementing the
gamification techniques in the training sessions is an
important task, but it is not an impossible thing to do.
Many organizations have started conducting such training
sessions for their employees, and they were successful.
Lowry and Silic, in their article, stated that specific designs
with specific information technology artifacts for particular
kinds of employees could be a key to the success of
applying game-based techniques in the training sessions.
This article supported the hypothesis in many ways. The
hypotheses state that game-based techniques can lead
to higher user security compliance, which was proven in
this article. Game-based technologies like the Kernel
theory, hedonic motivation system, and design science
research were studied, analyzed, and experimented in .
The results of the article proved that long-term research on
the specificity of the requirements of the employees, the
organization and the type of game-based techniques which
can work best on the situation, the successful
implementation of the kernel theory and a careful selection
of design science research could surely lead to the
success of the gamified training session.
In another article by Ryan J. Baxter, it is stated and proved
through a field study that game-based techniques are
successful in increasing and assuring the security
compliance at the user end. The only need is to implement
these gamified training sessions properly. The hypothesis
can surely be correct and work in the field if the game-
based training sessions are not too long that can bore the
employees, not executed on the wrong time or after a long
day job that can make the employees feel hectic and not
interested in the training and the training should be in
simple language that an already gamer or a non-gamer,
both can easily understand.
Once a training session is successful, the employees are
more focused, motivated, and knowledgeable. The
109 110
111
112
113
84
Passive voice
85
Passive voice
86
Passive voice
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 27 of 35
employees can then understand their tasks and work better
for the security and the demands of the users. This will
ultimately lead to a safer organization and safer user
security.
H2: A high state of flow in game-based security training
will lead to higher user security compliance.
This is the second hypothesis of this paper. For this
hypothesis, which states that flow is an essential element
for the successful implementation of the Gamification and
an immersive or high state of flow will result in an
increased rate of user security compliance, three articles
were chosen . The articles in support of this hypothesis
include (Florian Brühlmann. E Mekler, 2013), (Chul Woo
Yoo, 2018) and (Jeanne Nakamura, 2009). The second
positive hypothesis states that a high state of flow or an
immersive flow is the key to the success of a gamified
training and the success of a gamified training leads to a
higher assurance of the security of the users. Flow
elements are the most important things to consider while
we are talking about flow in the gamification context. The
hypothesis is correct, as illustrated by Chul Woo Yoo,
that the SETA effectiveness can lead to higher
psychological ownership, and higher psychological
ownership is proved in this article that it ensures a
higher user security compliance intention. If we focus on
the elements of the flow, there are nine elements, and each
aspect, if successfully undertaken, results in a higher user
security compliance intention. Chul Woo Yoo proves in his
article that an immersive flow directly links with the higher
user security compliance intention.
The immersive flow is initiated by the elements of
flow , including feedback, challenge, clear goals, social
interaction, immersion, feeling in control, and autonomy.
The immersive flow or a higher state of flow when
initiated, lead to effective security education, awareness,
and training. This further leads to the employees'
focused attention on the user and results in psychological
ownership (Chul Woo Yoo, 2018). Jeanne Nakamura states
the same thing and proves that this hypothesis is correct by
addressing that the flow is the cause of a psychological
ownership state, and this psychological ownership
114
115
116
117 118
119
120
121
122
123
124
125
87
[ ]
88
[ ] 89
Passive voice
90
[hamari Hamari]→
91
[lead leads]→
92
Passive voice 93
Passive voice
in relation to about→
trainings training→
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 28 of 35
combined with self-efficacy leads to a higher user security
compliance (Jeanne Nakamura, 2009). The second
hypothesis of this paper is correct and is proven in
another field study driven by Florian Brühlmann.
Brühlmann proved this hypothesis is right through the self-
determination element of the immersive flow (Florian
Brühlmann. E Mekler, 2013). Self-determination and other
aspects of flow like the sense of immersion, action-
awareness, concentration, and focus leads to an increase in
usability. This usability of the employees is proved to
enhance user security compliance intention. All of the keys
which can prove this hypothesis true is already
present in the literature.
Understanding this hypothesis is as simple as
understanding the basics of flow. Immersive flow by
Jeanne Namakura is a state of complete immersion of an
individual in any activity (Jeanne Nakamura, 2009). Now,
suppose, if an employee who is dealing with users, is
completely motivated, focused, and immersed in his job,
he will be sure to complete his task with full satisfaction.
This is what the hypothesis proposes. Successful
enactment of the factors of flow by an employee, like
challenge-skill base, concentration on hand at task, clear
goals, and action-awareness merging leads to an immersive
flow and an immersive flow leads to higher self-efficacy,
self-determination, and psychological ownership. The
psychological ownership and self-efficacy combined lead
to a higher state of user security compliance.
H3: A low state of flow in game-based security training
will lead to lower user security compliance.
For the third hypothesis, which states that flow and user
security compliance are again directly linked, and the low
state of flow in game-based security training leads to lower
user security compliance, three articles were chosen . The
articles in support of this hypothesis include (Alejandro
García-Jurado, 2018) (Juho hamari , 2014) and (Tom S.
Chan, 1999). Juho Hamari supported this hypothesis by
stating that each of the flow dimensions are separate
things (Juho hamari , 2014). An absence of any of the
dimensions of flow leads to an overall lower state of
flow or a lower efficacy of any dimension leads to
126
127
128
129 130
131
132
133
134
135
136
137
138
139
140
141
142 143 144
94
Repetitive word: presentation
95
Passive voice
96
[ and],
97
Repetitive word: article
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 29 of 35
lower state of flow . This lower state of flow results
in a lower level of motivation, learning, self-efficacy, and
self-determination.
Other than the lower state of flow of an employee by
himself/herself, the failed induction of flow through
training sessions can also lead to a lower state of flow .
Now, suppose, if the employees are already not motivated
and a gamified security training session also gives no
results due to the newness of the components of flow, this
will ultimately lead to a state where employees are more
confused and complexed. In this state, they would not be
able to conduct their job efficiently. They will have less
knowledge, lower levels of concentration, and a confused
mind regarding how to perform their tasks of the security
of their users. All of this will create aa a mess. Ultimately,
the result will be a less safe and up-to-the-mark
organization with less knowledgeable employees and
compromised user security compliance.
To conclude, all three hypotheses are positive hypotheses
that present that Gamification increases user security
compliance, and, in the Gamification, flow is directly
related to user security compliance. If the flow state is
higher, the user security compliance is higher, and if the
flow state is lower, the user security compliance is more
moderate. All the components of flow and user security
compliance are like a circle. If the loop breaks, the results
get distorted. The flow theory provides enough proof on
this topic. All three hypotheses are proven right from the
above-discussed literature. For a better understanding, the
flow theory is helpful enough, which states that the flow is
achieved through feedback, challenge, action-awareness,
clear goals, immersion, feeling in control, and autonomy.
Once the flow is achieved , it gives rise to self-
efficacy and psychological ownership. These two
combined leads to user security compliance intention.
This is the whole process of how the higher or lower
flow leads to a more upper or lower state of user security
compliance. Hence, the three hypotheses are accurate based
on the review literature and the investigations enacted in
that literature.
3.5 Conclusion
146 145 147
148
149
150
151
152 154 153
155
98
Passive voice
99
[the Generation] 100
Passive voice
101
Passive voice
102
Repetitive word: flow 103
Repetitive word: flow
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 30 of 35
To conclude, the three hypotheses of this paper are
justified by the articles mentioned above. It is proved
from the above review of literature that Game-based
training leads to higher-level user security compliance, A
high state of flow in game-based security training will lead
to higher user security compliance and A low state of
flow in game-based security training will lead to lower
user security compliance. Yet, there is a need for further
research in the field of gamified security training to find
solutions for the successful induction of flow based on
achieving a flow of all nine dimensions individually.
Furthermore, merely including a few gamification
components to a current framework is not the best
methodology. Equivalently, the rewards don't make an
exhausting purchase enjoyable over the long haul, game-
based training does not fix a terrible design. To know the
kind of motivation and flow, an employee needs to
undertake an efficient user security compliance might be
the optimal design of the game-based training.
156 157
158
159
104
Passive voice 105
Repetitive word: articles 106
Repetitive word: hypothesis 107
Repetitive word: hypothesis 108
Passive voice
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 31 of 35
109
Repetitive word: hypotheses 110
Repetitive word: techniques 111
Passive voice
112
Preposition at the end of a sentence
113
Overused word: surely
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 32 of 35
114
Unclear antecedent
115
Unclear antecedent
116
Repetitive word: flow
117
Passive voice 118
Repetitive word: articles
119
Repetitive word: higher
120
[Yoo ],
121
Passive voice
122
Passive voice 123
Repetitive word: flow
124
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 33 of 35
Repetitive word: flow
125
Unclear antecedent
126
Passive voice
127
Repetitive word: flow
128
Passive voice
129
Repetitive word: prove 130
Overused word: true
131
Repetitive word: understanding
132
Overused word: completely
133
[full] 134
Unclear antecedent
135
[ and],
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 34 of 35
136
Passive voice 137
Repetitive word: articles 138
[hamari Hamari]→
139
[are is]→ 140
[hamari Hamari]→ 141
Repetitive word: dimensions 142
Repetitive word: flow 143
[ or], 144
Repetitive word: dimension 145
Repetitive word: lower 146
[a lower] 147
Repetitive word: flow 148
Sentence fragment
149
Repetitive word: flow 150
Repetitive word: flow
Grammarly GrammarlyReport generated on Monday, Aug 17, 2020, 09:39 PM Page 35 of 35
151
Passive voice
152
Repetitive word: flow 153
Passive voice 154
Repetitive word: achieved
155
Unclear antecedent
156
Passive voice 157
Passive voice
158
Repetitive word: flow
159
Repetitive word: flow