Friday, February 10, 2017

Review: 34th Annual Academic Chairperson's Conference 2017

I've taken over as Department Head approximately 8 months ago and our Provost took us to this conference so we could learn some of the tips, tricks, and just generally, the ropes in general about running a department. I have to say I'm impressed. I've had a session or two that were perhaps not particularly valuable. But for the most part, most sessions have been extremely valuable. So, to share a little of what I learned (and to document it for myself for future reference), I will share with each of you here my take aways from each session I attended.

1. Thursday 8:00-9:00: Keynote Address from Dr. Carolyn Jarmon, Rochester: "Addressing Traditional Trade-Offs". She presented something she referred to as the 'iron triangle'. At each point, were cost, access, and student learning. Changing one affects each of the other corners of the triangle. There are pressures from state legislatures to enlarge class sizes and cut costs. Per the iron triangle, that might suggest that student learning has to suffer. But, by leveraging I.T. and through course redesign, this mandate just might be achievable. Having participated in course redesign at my institution, I found her argument inspiring and encouraging. But, course redesign can be used not just to improve student learning. It can also be used to reduce instructional costs, thus helping to achieve the mandate from many legislatures. Team effort is key from all constituents including administration, faculty, I.T., and assessment experts. Results help to reinforce the use of course redesign. Cost savings range between 5% and 81% with an average of 34%. Improved learning occurred in 72% of the cases. Why not the other 28%? Recall, a goal might be to reduce costs rather than improving student learning. If student learning is already strong but costly, this makes perfect sense. Introductory courses are usually well suited. I am thinking of BCIS 1305 and Marketing 2314 from our department, the introductory CIS and Principles of Marketing respectively. The point is, course redesign transcends disciplines. It tends to use less lecture and involve more engagement. It tends to use more software (that can automatically measure student involvement). It also includes deadlines to provide structure for students. Lastly, course redesign results in increased feedback and opportunity for mastery from students. One interesting side example given was a math lab in which math students from several different courses (algebra, trig, and calculus) might be working on computers, working through problems. A faculty member, along with GAs (it was a particularly large lab) staff the lab and students with questions place a red cup on top of their computer tower whenever they have a question. GAs triage questions and pass the more complicated questions on up to faculty when necessary. It was equated to the one room school house. Her last "take away" was what to do when we got home:

  1. Identify the problem
  2. Identify the team and inform others of redesign
  3. Review other re-designs on NCAT and others
  4. Review NCAT guide for academic area
  5. Visit other institutions who have re-designed with success
  6. Review resources available for the re-design
  7. Establish the plan and get going (no analysis paralysis)
She concluded with her contact information at www.theNCAT.org and cjarmon@theNCAT.org. Overall, it was an excellent kick off to the conference and as previously mentioned, having gone through a course re-design and now being department head, it has me thinking about some other classes that we should target.

2. My first regular session was "Performance Management Or "Herding Cats"? Strategies to Support Faculty Success by D. Bratson-Prince and R. Bagley of Iowa State University. This one set the bar high as it was one of, if not the best session I attended. LOTS of great information. As department heads, we manage resources. Resources come in several different forms: funding, space, and of course, people. As it relates to people we want to develop successful faculty. But, there are challenges: research demands, lack/loss of motivation, power related issues (tenured vs. non-tenured relationships), etc. To be successful, you must understand "the animal". To herd cats, you simply have to know what motivates them. We were then presented with two slides. The first was a picture of cats all over the place, doing their own things. The next was of each cat, lined up...at a food dish. Clearly, food was their motivation. Some might argue that faculty fall into a similar camp. What makes working with faculty difficult in the first place? It is by design. They are by their very nature, intelligent, independent, opinionated thinkers. In order to manage their performance, you need to address four things:
  1. Process (for expectations and providing feedback)
  2. Formative and Evaluative
  3. Outcomes Based
  4. Challenging
But, the benefits of performance management are numerous:
  1. Faculty know where they stand
  2. Chairs gain insights into motivations
  3. It enables you to retain productive people
  4. It contributes to the overall success of the team
  5. It contributes to their success-salary, promotion, recognition
Set and communicate expectations, be specific, and hold people accountable. Some of the pitfalls include:
  1. Knowing what your role is; being unclear is problematic
  2. Providing unclear, vague, or ambiguous performance expectations
  3. Avoid minimizing, justifying, or ignoring a problem
  4. Avoid letting a pattern develop
  5. You must get to the root of a problem/cause
  6. Don't let the past pile on
  7. Do not make it personal. Keep it professional
Document
  1. Write a narrative story. See my second to last entry in this post.
  2. Keep factual, not personal
  3. Shows you treated them fairly, consistently, within policy
  4. Proves you put them on notice of expectations, performance, or behavior
  5. Establishes timeline
As part of this, having an inclusivity or collegiality statement in faculty handbook that covers bullying, harassment, etc might be helpful. They also mentioned the use of DISC four quadrants as being a useful tool to facilitate communications with faculty. Back to motivations, 6 sources include personal, social, structural, ...  All in all, this was an excellent presentation which opened my eyes as to some of the breadth of my responsibilities as the head of my department.

3. My next session was "Developing a Succession and Transition Plan for Chairs". I have to admit, this one was a bit odd, particularly since my Provost sat in on the same session. She told me I became department head too recently to be considering succession. Nevertheless, I took away some good tips and tricks from this one as well. Essentially, we have both formal and informal approaches for developing future chairs. Formal methods include having an assistant chair position or support for other leadership positions in which faculty can develop leadership capability. Informal methods include tapping search committee chairs or "Friday Chairs", those who fill in for the chair when they are away on business/vacation. One of the challenges for outgoing chairs is recognizing that you won't get everything done that you want to. I can easily see this issue and I myself sometimes feel overwhelmed just with the day to day running of the department. In this sense, this conference did not help as I have identified several holes in how I have run the department so for. So, I have some catching up to do there. Anyway, some of the challenges for an incoming chair include:
  • Paperwork (the volume of it)
  • Adjustments to relationships (I noticed this one myself)
  • Making the department yours
  • The feeling that you need to know everything and always be available
Some of the most valuable tools at your disposal as an incoming department head/chair include:
  • Consultations and warnings
  • Administrative assistants
  • Professional friendships: cohorts and mentorships
  • Meetings (informal and retreats)
  • Forward or CC on emails
  • Continuing relationship with previous department chair/head if possible. They can be a great resource due to their institutional knowledge.
Lessons learned for future department head transitions:
  • Solve personnel issues first (re-appointments, P&T, etc.)
  • Discussion of the budget
  • Identify programs or initiatives that need to be kept or can be discarded from the outgoing department head/chair
  • Ask the question "Does this decision make the job harder for the next person?"
  • Share and include the incoming chair in memos, calendars, and checklists
  • Go meet with the Registrar and develop a relationship. They know about courses, scheduling, etc.
  • Email students about changes (letting them know that you are the new department head)
  • Keep a calendar about important things due so you know what is coming up next year.
This one was not quite as well presented as the first session I attended but the content was quite good. I certainly came away with some great nuggets that I can put into practice.

4. The next session I attended was titled "Developing and Supporting the Diversity of Chairpersons Roles. This was presented by several faculty from Augusta University. It was not quite what the title indicated but the description in the conference catalog is what attracted me to this session. They focused on a Chair Professional Development program that they have at their university. Awesome idea, huh? Why don't we have something like this? It is included in their equivalent to CII in which they develop not only instructor's/faculty teaching ability, but also, administrator's (chairs specifically) leadership ability. They run this out of the Provost's Office, sidestepping deans so they have direct communication. They have monthly meetings where they discuss resources and develop leadership. They facilitate the sharing of information and how to handle challenges. This one ties in to the previous session in that they emphasized the need to use delegation to help develop faculty for future administrative roles. The outcome of their development program is that it provides a safe place to vent (to your new peers of fellow department heads as opposed to faculty), results in more information sharing, skills development, lessons learned (FAQs), and even a Chair Resource Handbook. I found this one helpful. There was not perhaps the instant gratification of nuggets I could go back and use immediately. But, it reinforced previous sessions AND provided the nucleus of an idea that I would like to see our university incorporate at some point in the future.

5. My second to last session of the day was titled "Leveraging Technology for the Recruitment of Students and Faculty". This was led by W. Hoon and C. Hirschler. Having an interest in promoting our department and programs as well as an interest in social media, I thought this session had the potential to be an interesting session. In the end, it was not quite what I expected but I did find it interesting. Get the program affiliated with every site you can to increase the links and raise your Google Page Rank. For example, he brought up Learn.Org as an example where he spent some time completing out their profile which to a lesser or greater degree, increases the visibility of his program. I would add Cappex.com as another possibility. I need to spend some time looking into this further but I can see the benefit of doing so. Make sure the university's site is consistent in terms of content with your own site as well as both being current. Include pictures of students in action, engaged with activities relevant to their major. Video content is another winner. It does not have to be studio quality. Genuine is more important. Include a photo gallery. Lots of photos of students in action. Include multiple people/faculty as administrators to your FB page so they can post pics and whatnot to the page. Make use of Twitter and Instragram as well. They have a faculty member (it rotates) that has lunch in the cafeteria with their students to help answer questions and build a rapport and they just happen to take pictures there and post. They even tried a crowd funding campaign to raise funds for new equipment. This might be a good idea for our AITP to help fund travel to regional and national competitions!!! Include hyperlinks in your recruiting letters, email videos and show them at open houses, connect with alumni via LinkedIn and email students and ask them to like us on Facebook. Make sure your LinkedIn profile is solid and ask for recommendations and use videos. LinkedIn can be useful in finding quality adjunct professors. Overall, this was a decent session though I would not say anything earth shattering came from it. One point that I think they did help emphasize is that this is not easy. It takes work. All these tools are neat but content is king and generating and managing content can be time consuming.

6. The final session of the day was "A Blended Family: Leadership of Multi-Disciplinary Departments" by B. Bonnekessen and C. Patterson of Pittsburg State University. Having both Marketing and CIS in our department, I was interested in getting some of their insight. Unfortunately, I did not get a lot out of it. Their examples included departments with LOTS of different disciplines, in some cases 10 or more. I simply have two so their rationale behind having program coordinators did not seem particularly relevant in my situation. But, having little background in Marketing, this might be something to consider at some point if necessary. One take away I did get was that one of the presenters served as a chair in such an environment as an Assistant Professor. This led to the rather uncomfortable situation of doing performance evaluations on professors who outranked her. Her solution was to name three senior faculty members to a faculty review committee whom she worked with to perform reviews. As a result, she could argue that faculty were evaluated by not just her but also senior members of faculty peers. As a result, she could deflect some of the potential ire of some who might have questioned her legitimacy to review their work. That was a pretty nifty move. Regarding their use of program coordinators, they use a 3 year cycle to not allow anyone to dominate a program for too long. They also indicated that an administrative assistant is a MUST. I have to agree on that. They hold a lot of institutional knowledge. Good admins are invaluable.

The next day, the opening session was a panel discussion. I really did not get much out of this session but I did hear the interesting statistic that the University of New Orleans dropped from being 75% state funded to 25% in, I believe the guy said, 9 years. 9 YEARS!!! Amazing. This is a telling tale about the assault on higher education. We need to re-frame the how and why we invest in higher education. For me personally, I look at it like a research and development investment for a corporation. Sure, a corporation and drop research and development spending. It looks good on the books today. But, the real impact is 20 years in the future. But, that's just my own little soap box.

1. The first actual session of the day was quite interesting. It was titled "The Four Quadrants of Administrative Effectiveness" by Robert Jenkins. The scales for each dimension were Responsibility and Control. We took a scaled down version of the instrument and while there was some question of validity (the instrument is in beta and we essentially we part of the validation process), many of us, myself included turned out to fall in the High Control, High Responsibility quadrant. More on that in a moment. The Low Control, High Responsibility (LCHR) group tends to represent the best administrators. They are liked and respected. They do not pass blame and they accept responsibility. They share credit and do not micro manage. They hire quality people and let them do their job. They trust people, seek consensus but are not afraid to make tough decisions. High Control, High Responsibility (HCHR), you know, like me;) tend to be well liked, often beloved. They give everything to the job. They sweat detail, start early and leave late. They send emails at 3 AM. They are very effective...to a point. They tend to burn out. They can also burn those around them out too...to the point that eventually, people start to avoid them, not because they do not like them but because they are afraid they are going to have more work assigned to them:( Low Control, Low Responsibility (LCLR) tend to be the least effective. They leave people alone (which faculty like) but there is a complete lack of direction. The are not control freaks and do not micro manage. They do not expect much of others or even themselves. They are rotten leaders because they do not lead. The autonomy is great until you need someone to steer the ship in which case it has to be a collective faculty endeavor. The last group, High Control, Low Responsibility (HCLR) are also ineffective. They can sometimes get short term gains but usually at the expense or morale. They constantly point fingers, take credit, always come from the position of "being the boss", can sometimes be irrationally demanding, micro manage, sneer at those in the "trenches". They are usually shown the door but not until they have done great damage to morale. In order to move your point to a more desirable spot on the control dimension, there are four key factors to consider: balance, empathy, transparency, and trust. Regarding balance, he gave the example of keeping all the balls in the air. But, the problem with that is that it is less about balance and more about being OCD. True balance is more about being in the moment, with the people around you, when you are supposed to be, doing what you are supposed to be doing. Balance is about scheduling, de-cluttering, and harmony. In order to do this, you need to prioritize. This leads to the 7 questions of prioritization:
  1. Does this need to be done?
  2. Why does this need to be done?
  3. When does this need to be done?
  4. Do I have to be the one to do it?
  5. How does it fit into my personal mission (statement)?
  6. What are the consequences of neglecting or putting it off?
  7. Who is relying on me to do this?
Two types of balance include work-life balance (often discussed) and work-work balance, which is what he addressed. Essentially, there are three types of tasks: those we like, don't like, and indifferent about. We need to find an equitable equilibrium. Over your career, we should be moving to more 'like' and less 'don't like'. This leads to the paradox of leadership. Advancing to the department head role seems to take a step backwards on the work-work continuum. The choices are to step down, suck it up, or move to a better work-work balance where you are doing more things you like and fewer things you don't like. Regarding empathy, it takes self awareness and humility. Recognize that you are not the center of the universe and stop dwelling on problems to solve other's problems. If you understand where people are coming from, you might be less inclined to control everything they do. Transparency is a function of honesty. It requires that you relinquish control. It also require discretion. despite the need for transparency, some things must be "hidden" (i.e. medical issues of faculty). But, you should never have hidden agendas. The last way to move the point on the control dimension is through trust. This is another function of honesty. Trust is a two way street. You must give it if you expect it. Leaders that don't trust tend to micro-manage. They roam the halls to check up on people which does not tend to go over well with faculty and can have a devastating effect on morale. Trust needs to be your default position. To show trust, treat people like professionals. deal with problems face-to-face, privately. Just because you have one bad apple, do not assume the rest are bad too. Be careful how you respond to complaints. Most complaints require no response whatsoever. Always assume your people are right until you know otherwise. Keep confidences (when able to). Tell the truth and follow through. Be reliable, predictable, and let people know you have their backs. Now, moving the point on the responsibility dimension. Know who you answer to, make sure you meet acceptable standards, and accept the consequences. You may be accountable to many. You may get to set some of the standards. But, you must accept the consequences for not only yourself, but also your academic unit. Integrity is another way to move on the responsibility continuum. It is a function of honesty. To thine own self be true. It boils down to simple truth telling. Fairness is another approach. This is a function of justice. But, it does not mean that life is always fair or treating everyone the same in every circumstance. He gave a little league example in which he would not let a player play a particular position not because he was truing to be mean but rather because they player was not yet performing at a high enough level and was liable to get hit by a hard, line drive ball. However, you do need to insure equality of opportunity. Make sure everyone has the same opportunity. Service is another way to move on the continuum. This too is a function of humility. Set aside egos. At times, step aside and let others lead. Cultivate the leadership of others. He gave the example of serving on a committee within the department BUT, make someone else the committee chair. Finally, you need courage to move on the responsibility continuum. There is the classic definition of courage as not being the absence of fear but rather, conquering some obstacle despite fear. There are several models of courage: personal, physical, political, and societal; self>others>principle, etc. But, you need the courage to do what is right. This will help you build trust and become a better leader. You need courage to take risks. To trust those around you, you need courage to take the risk that they will complete the task. You need courage to buck trends. Everyone says "think outside the box" but they do not really mean it. Not because they fear failure but because they fear being perceived as incompetent. You need courage to lead. "If the leader is going to be an a-hole, the leader might as well be me." This means there is not leading from behind. True leaders are out front, whether they want to be or not. Finally, you need courage to confront. But, it does not have to be done with negativity. Approach with humility and in a constructive manner.

2. The next session was shorter but really needed a little more time. It was titled "The Art of C.Y.A.: Documentation for Department Chairs" by C. Barrick of the University of Arkansas at Fort Smith. The message was clear: keep good records. Why? To support, inform, and justify future action. Evaluations can improve performance, can lead to evidence based decisions, and and provides a picture of what happened. Keeping good records is part of the job as an administrator. It is like keeping grades for faculty. What needs to be documented? Faculty events/incidents (complaints, inappropriate behavior, etc.), significant meetings/conversations, and student events/incidents. But, documentation does not have to only include negative things. You can also document student and faculty awards for example. The speaker the discussed his tool of choice: "Memo For Record". 90% of the time, this is just for your own record and does not go into an employee or student's file. It needs to become a record of habit, not just a document. The format does not really matter but needs to include who created, what it is regarding, and the date as well as narrative, bullet points or whatever to communicate the event. The content needs to include what happened and what was said. Do not interject opinion. Just the facts. First or third person is preferred with third being more preferable. Remember who potential reader might be; provosts, presidents, deans, lawyers, etc. Use full names and titles and do not abbreviate. Provide background when necessary or give specific references to previous documentation if it exists. Such documentation should be done as soon after an event as possible. Accuracy and detail are important. This does not mean it has to be a long, drawn out task. One page should suffice in most instances. Clear your schedule if necessary. Perhaps the last few minutes of each day is appropriate. To speed the process, have a template setup. In some instances, you might even be able to record such meetings. To me, depending on the circumstances, this could include using a web cam in the office to record, with everyone's knowledge, meetings between faculty, students, or whomever. As for who to include, recognize that most MFR will never see the light of day. If necessary, email the dean or other appropriate party. Email provides a time-stamp which can help strengthen your documentation. It was during this discussion that I though about including an MFR template in each faculty Google Drive folder as well as a more generic student folder. File name should be MFR-date-and then the RE line in the memo. The last point he made was on papering. Do not, under any circumstances, start to over document after and event occurred. It is too easy to observe and weakens your case. You must consistently and repeatedly document all events, regardless of who it is.

3. The final session I attended was titled "The Art and Science of Evaluating Online Programs" by M. Smith and K. Alder of A.T. Still University. Having an online program, our MS-IS program, I thought this would be interesting. Also, given my background in assessment, not that I am a guru by any stretch, it just added to my curiosity. But, it was not quite what I expected, not that I really knew what to expect. But, I did still have some take aways. They use TK20  for student surveys. They survey student half way through the semester. They survey them again at the end of the semester. They give their faculty the curriculum (they are some sort of health/medical school) and so the instructors themselves are also surveyed at the end of the semester. They survey graduates and ask questions like what they liked, didn't like, courses, etc. This survey also includes collecting employer information so they can then turn around and survey employers which they do once per year. They usually have to mail those surveys but the information they get is invaluable and helps them validate their program competencies or objectives. They also conduct alumni surveys.

All in all, this was a great conference. I came away with some great information and some ideas about things we should consider doing at Tarleton State University. I saw real value in this and mentioned to our provost who also attended, that I could see real value in experienced chair returning periodically to kind of "retool". I highly recommend this conference if you are moving to or are already in higher education administration.http://conferences.k-state.edu/academicchairpersons/

Sunday, November 6, 2016

Review: 2016 Social Media Conference

I attended the 2016 Social Media Conference yet again this year. I think it was the best one I have attended, with each session giving me little tidbits of information about how to better manage and utilize my use of social media as a professional and in my classes. This is not to say that the conference can't be improved. I would like to see stronger session on leveraging some of the analytics available in some of the platforms as well as to see a track dedicated to academic research revolving around social media. But, from top to bottom, this year's conference was the best I have attended.

For my first session, I attended a session on "In Introduction to Social Network Analysis" bu Vivian Ta (@VivianTa22). A doctoral student from UTA, she presented last year and was back again. She described social network analysis as mapping and measuring the flow of information. It enables you to identify connectors, influencers, bridges, and isolates. The methodology allows you to track the spread of disease, sexual relationships, collaborators, business, law enforcement, etc. The value of social network analysis is that it allows you to identify data and patterns of information flow. There are two types of social network analyses: egocentric and socio-centric. Egocentric revolves around a single person to demonstrate economic success, depression, etc. Socio-centric social network analysis focuses on large groups to describe groups of people to give insight into concentration of power, spread of disease, group dynamics, etc. There are three types of measures used to analyze social network relationships (referred to as centrality measures): degrees, betweenness, and closeness. Degrees refers to the number of relationship connections each node has. Betweenness refers to nodes that link together multiple groups. They represent single points of failure and can be important linkages in terms of allowing information to travel between groups. Lastly, closeness refers to how quickly information can travel between nodes. As for actually gathering the data, you can utilize direct measures such as surveys but this can be time consuming and difficult. Indirect measures can come from organizations, citation analyses, co-authors, memberships in organizations etc. This is a cheaper approach but does not indicate how nodes are truly related to one another. Still another approach is to use data scraping, web harvesting, or data extraction techniques to pull data directly from user's social media accounts. For example, you can harvest likes, follows, friends, reply to's, retweets, comments, tags, etc. See OutWit Hub for an example of a data scraper. As for analyzing the data retrieved, there are several FREE platforms: NodeXL, Pajek, UCInet, NetDraw, Mag. e, Guess, R Packages for SNA, and Gephi. You can examine the frequency of interactions, types of interactions or flows, as well as the similarity of characteristics (status, location, educations, beliefs, etc.). This was a nice presentation that gave me a research idea so in my mind, it was excellent.

The second session I attended was titled "How to Use Social Media in Higher Education to Tell Your Program's Story" by Dr. Becker and Dr. Putman. The started off by citing Hoover, 2015 who found that interacting with current students and staff through social media is more effective that interacting with them face to face. They stressed the need to align social media efforts with strategic goals and that you need a dedicated social media person to handle efforts 10-15 hours per week. They used a work-study position for this which is funded mostly through the federal government, thus reducing the funding requirement on the part of the department. Start by developing strategies and goals and develop a consistent message across platforms. It would not be wise to have a very conservative message shared through one outlet and then a very wild approach on another. Develop a hashtag for your department. They noted that it is challenging to consistently post, create messages with audience appeal, and dedicate time of an employee. You should post photos with your messages as it leads to significantly more likes, comments, and click throughs. Short posts and pose a question also tend to be more effective. Finally, the best times of the day to post are around 9:00 AM and 4:45 PM so, 1-2 times per day. This was a good presentation, which gave me some good ideas for managing our own department's use of social media.

The third session was titled "Twitter for Educators - Network, Learn, Grow" by Yvonne Mulhern. She started off with an interesting quote from someone I did not catch: "Twitter makes me like people I've never met. Facebook makes me hate people I know." She talked about using Twitter for professional development, self-promotion, and the use of Twitter Lists. Follow people you admire, leaders in your field, etc for professional development. Tweet publications, research ideas, etc. Finally, follow other's Twitter Lists which enables you to more efficiently follow leaders in your field. Follow HigherEdJobs or Chronicles Jobs. The idea is to develop your own personal learning network (PLN). There are also several tools that enable you to streamline your use of Twitter: Twistori.com, TweetReports.com and do not forget to look at Twitter analytics.

The fourth session was presented by Dr. Goen and Dr. Stafford and was titled "Remaining Legal and Combating Trolls on Periscope, Facebook Live, and Meerkat". They limited the discussion of Meerkat given their recent demise. They first defined a troll as an individual that visits a page to post insulting, off-topic comments to provoke some sort of emotional response. In general, they identified two different types of trolls: spammer trolls and disruptive trolls. Spammer trolls are all about them, selling their stuff, etc. Disruptive trolls spew insults, often sexual, violent posts, etc. Regardless of the type of troll, there are ways to combat trolls. On Periscope, you can set a post to follow only which means only those who follow you may post a comment. All others can only watch. You can also block users on a live broadcast. This does not remove a negative comment but it does prevent them from making additional ones. Finally, you can set a broadcast to private which only enables those following you to make comments. There are similar tools on Facebook (FB). On FB, yo ucan report/block a person from your page. The report aspect provides FB with information about your objection and allows you to continue to view the other's account. If you simply block a user, you do not have to report anything but by doing so, you can no longer see the other's account. You can also adjust your general privacy settings to limit what others can see. Alternatively, you can customize each post to limit its exposure. Finally, you should only accept friend requests from people you know.

The final session was over YouTube by Dr. Mitzi Lewis. Titled "How to Make the Most of Your YouTube Channel", Dr. Lewis boiled it down to three essential areas: Brand Your Channel, Be Found, and Keep 'em Watching. For Branding Your Channel, know your mission and post videos that are directly relevant to it. If you need to deviate, consider adding another channel. Make sure your banner, name, and icon are consistent in terms of terms, colors, style, etc. You are trying to give off a consistent image. Have a good, relevant channel trailer that is, ideally, 30-60 seconds. Finally, include channel sections to groups similar/related videos. For Be Found, make sure your thumbnails are images that are relevant to the video content. She gave the example of Jimmy Kimmel videos in which then thumbnail is usually an image of the guest being interviewed. Make sure the titles use words that people will search for. Put the meat of your descriptions early in the narrative, so they can be seen without hitting "more." If you want to identify good key words to include, google.com/trends/explore can be helpful. Finally, keep tags short and meaningful. Finally, for the Keep 'em Watching group, Dr. Lewis suggested maximizing watching time by hooking them first and then let them watch. So, given them a tease, intro, and then discuss your topic. It is extremely important to hook them early. If you use playlists to organize related videos, limit the number of videos in the playlist to the teens or so. Use a watermark which will exist on all of your videos. Finally, regularly upload videos so subsribers have something to visit. For other helpful tips and tricks, she recommended creatoracademy.youtube.com.

This year's conference was better than years past. Again, I would like to see an academic research track included as well as some strong sessions on analytics. But, this is a nice little conference that is applicable to this in higher education, primary and secondary school, as well as businesses and other organizations. So, plan on attending next year!

Thursday, November 3, 2016

Review: ISSA 2016 International Conference

As a new ISSA member as of late last year, I attended my first ISSA conference, conveniently located (for me) in Dallas Texas. Being used to academic conferences myself, I was not quite sure what to expect. I knew it was going to be more practitioner based and practitioner based it was...largely from a fairly managerial perspective. So, that was in my favor. So, here's a recap of the session I attended.

For me, the first day was the weaker of the two days but the first session of the day was the strongest. It was titled "Architecting Your Cyber-security Organization For Big Data, Mobile, Cloud, and Digital Innovation" by Mr. David Foote. He discussed the importance of aligning business and security objectives and that part of making sure that happens is having CISOs report to Boards of Directors rather than to CIOs. He argued that part of what makes managing so difficult is due to churn within the field. This is a result, he argued, of being spread too thin and burnout as experienced cyber-security specialists are constantly having to re-tune because of disruptive technologies such as Cloud, Big Data, IoT, etc.). According to his research, cyber-security jobs require more certifications than other IT jobs and that there are roughly only 1000 top level security experts compared to a need for 10,000 to 30,000. This brought him to the point that we are in deep need of "people architecture", an alignment of people, programs, practices, and technology. The benefit is an optimization of assets, improved decision making, minimizing unwanted circumstances, etc. Finally, Mr. Foote, discussed the need for consistent job titles and skills across organizations and industries. The lack of such a consistent job definition makes it hard to compare, for exam, a system administrator for one organization to a system administrator for another organization. Mr. Foote did an excellent job presenting and I would highly recommend attending other presentations he puts on.

The second session I attended was not quite as good but I did still come away with some good content. It was titled "Improving Incident Response Plan With Advanced Exercises" by Chris Evans. He stressed the need for "pre-incident" training in order to develop muscle memory. The goal is to stretch beyond just compliance. He described several ways of doing this: workshops, table top exercises, games, simulations, drills, and full scale exercises from least to most complex with the more complex yielding more tangible benefits but require more investment of time, resources, and expertise. The first step is to develop the objectives so that the people that need to participate can be identified. The key take away was that we need to evaluate > test > assess > drill.

The third session on day one was titled "Cyber Law Update". The presenter struggled on this one. She was neither a technical person nor a manager of technical people. She was, I believe, an insurance person. But, she found herself being corrected several times by the audience. Nevertheless, there was some good content to come out of the presentation. One of the key points was regarding the establishment of FTC authority as it relates to cyber-security breaches. She discussed LabMD who was not liable for the breach but rather, for the failure to take "reasonable" security measures. Another valuable contribution from this presentation was that the inability to show injury is what stops most law suits against companies from being successful. Emotional distress does not count. You must show some sort of physical injury. If you cannot show what or how much you lost, you have no case.

The forth session of the day was titled " Posture Makes Perfect: Cyber Residual Risk Scoring". This one was interesting. The presenter was a little unclear in terms of specifics on his scoring model but the general idea was a calculation that gave you a residual which represented risk. He briefly mentioned threat maps and displayed one by Kaspersky and mentioned the Norse Map. I have seen these before but never spent much time looking at them. Having said that, in looking through my notes for this blog post, I Googled them and ran across a site that lists both of these as well as several others. These are pretty slick and can be interesting and compelling when trying to discuss how pervasive security issues are. He also reference the over referenced (his words) Sun Tzu's quote about know your enemy, know yourself, ... While he made the argument through the process he was advocating that you could know your enemy, he started off stating that given the complex threat environment, that you could not know your enemy. This seemed more realistic to me. There are nation states, organized crime, hacktivists, cyber criminals, etc. This make make it seemingly impossible to know your enemy with certainty, at least without a delay to properly investigate. There are just too many possibilities. But, it does suggest that we need to develop methods to more quickly identify these sources so that we can more adequately combat threats. He finished up talking about there being lots of standards and lots of certifications that demonstrate or express proficiency as it relates to assessing, developing, and implementing security in organizations. Despite all of this, breaches continue to occur. Touche!

There was a fifth session for the day but I had to leave. Day two was really pretty solid. All the session were quite good I would say. For my first session on day two, I attended Advances in Security Risk Assessments". Presented by Mr. Doug Landoll, he started with an Einstein quote: "We cannot solve our problems with the same thinking we used when we created them." He talked about the threat calculation, which ever one you use, needs some sort of data. You can get that data from many different places. This may be as simply as a survey; "Do you have a firewall in place?" ... He stated that CISO's are in high demand and that if you examine job requirements on job posting sites, the requirements can all be boiled down to "reducing risk." In order to determine risk, the process for determining a risk score is important. You have to examine controls that are in place. For example, what is the hiring process like? You need to establish physical and logical boundaries to your assessment. You also need to apply a legitimate framework. In his opinion, some "frameworks" are not frameworks but are really just a collection of a few best practices (i.e. SOX, HIPPA, PCI, etc.). Legitimate frameworks include COBIT, NIST, ISO 27001, Cyber-Security Framework, FISMA, etc. With a framework identified, you need to have it mapped (hopefully it is already mapped by a good source) to a standard such as PCI. His point here was that standards and regulations are not frameworks. He then pointed to an article he published on LinkedIn. For assessment, he mentioned RIIOT: review documents, inspect, interview, and observe. Combine multiple approaches. To do good assessment, you need objectivity, expertise, and quality data. Finally, he plugged another person's book on quantitative assessment (Doug Hubbard). Follow this presenter on LinkedIn.

The second presentation on day two was titled "Culture Changes, Communicating Cyber Risk in Business Terms." One of the panelists stated that technology was similar to dog years, referring to the speed of change. The concept of nation states launching cyber attacks is recent. attack surfaces have mushroomed. It was also pointed out that the boundary of the enterprise is becoming harder to define as we rely more and BYOD devices, cloud services, etc. When asked about some of the recent drivers of culture change, the data breach at the Office of Personnel Management was brought up as was the Mirai DDoS attack and Dewall. The interesting thing about this last one was they were held responsible, not for a data breach, but rather for claiming through advertising that their systems were more secure than they actually were. Another example of driving a culture of change was ransom-ware and the interaction between victims and hackers. The panel concluded by discussing some of the existing standards (NIST, ISO 27005, etc.) and the focus on IT security risk and that we need to refocus on enterprise risk instead. I read into this an alignment of security and business objectives.

The third session I attended for the day was titled "Stepwise Security - A Planned Path to Reducing Risk" by Wade Tongen. He described the "de-perimeterization" of organizations and how that makes securing them difficult. Per the 2016 Verizon Data Breach Report, 63% of breaches occur as a result of weak, default, or stolen passwords. He mentioned the need for identity assurance because users have multiple identities (i.e. personal, professional, privileged, non-privileged). There is a need for consolidated identities. Fragmented identities result in sticky notes, use of same password for multiple systems, spreadsheets, etc. Use multifactor authentication EVERYWHERE. Organizations need role based provisioning so that applications, services, licenses etc. are all associated with a role so that when that role changes, access changes accordingly. Finally, the speed with which we can identify perpetrators, maximizes the chance of being able to do something about it. He used a convenience store robbery as an example. If it is robbed and you can give the police and accurate description quickly, they are more likely to be able to do something about it than if you can't provide them with evidence (such as video surveillance) for several days.

The final session I attended on day 2 was over Mr. Robot and whether or not it was an accurate depiction of a hacker's perspective. A panel session, the consensus was that it was. I left this session as I did not really see much value in the discussion. Overall, it was a good experience. It was new to me. As I mentioned, I am used to academic conferences. But, this was a nice conference to attend; one that I can do some further research about some of these concepts and take bake and use in my classes.

#BCIS5304 #BCIS3347 #ISSEConf

Tuesday, September 13, 2016

Review: Tarleton School of Criminology Cybersecurity 2016 Summit

Today, I attended the Tarleton School of Criminology Cybersecurity 2016 Summit held at the George W. Bush Presidential Library. I have to say that it was extremely well done. The various speakers brought forth an upbeat, hopeful message about the future of cybersecurity. With presentations from former military, law enforcement, lawyers, professors, and consultants, it was packed full of useful information.



One of the nice little nuggets I ran across was the concept of the "kill chain" presented by Col Jeff Schilling (ret). Naturally, this came from one of the former military presenters. A quick Google and the meaning behind it was clear and the extension to the field of cybersecurity could be easily extrapolated. Essentially, the kill chain is all the steps necessary to successfully eliminate a target. As it relates to cybersecurity, it would simply be all the steps necessary to compromise a target (read data). Remove any step in the kill chain and the objective of compromise cannot be completed. Now, here's the kicker. As security professionals, you can attack the kill chain at each and every stage OR you can focus your efforts on a single stage. Basically, this was the argument made today. The point is not to ignore all the other stages. Patching is still important. So it user education. But focus on the data. Focus on the prize.



The thought process behind this is that if we spread our focus on all steps in the kill chain, it divides our focus and we become less effective. As long as we do not lose sight on our most valuable asset, we can focus our efforts where we can be most efficient and effective.



We also had presentations from the Secret Service as well as the FBI (no photos or names please).



Our keynote during lunch was Mr. Brian Sartin, Managing Director Verizon RISK Services over Verizon's 2016 data breach report. No surprises here. Same thing as last year. Threats continue to grow, particularly as they relate to nation state hacking/espionage.



Then we had Candy Heath, AUSA and Lead Cyber Attorney for the United States Northern District of Texas confirm some of the keynote speaker's findings that the vast majority of those compromised don't know it. Rather, one a perpetrator's is taken into custody and their systems are evaluated, numerous targets (sometimes dozens to hundreds) are discovered. This explains the concept of why it takes so long for organizations to discover that a breach has occurred. They are not discovering the breach. Others are...usually about 9 months after the breach originates.



Then a panel discussion over the state of educating security professionals and meeting the needs of employers occurred. The consensus was that we have a lot of work to do. Security professionals are very mobile. They can afford to be. They have highly sought after skills and few competitors. Depending on the presenter, there is a roughly 200,000 person shortage in this country. And, they predicted the problem would get worse. They also recognized the even within the general field of security, that there are specializations and the sometimes, an organization has security specialists, just not the specific ones they need.



Shawn Tuma, another attorney spoke about representing organizations that were the target of cyber attacks and noted the importance of simply have procedures in place and following them. Failure to protect data in and of itself is not the problem. But, failing to take reasonable precautions and not following established procedures opens up an organization to liability.



The second to last speaker was Chuck Easttom, computer scientist and author. He teaches, consults, testifies (prosecution and defense), etc. Bright guy. Would love to take some of his classes. He outlined an incident response template. The big take away from that was about verifying the credentials of the forensic expert. By that, he meant actually verify. Do not just take their word for it. Make sure they do the work and/or that they supervise those who do.



Lastly, Randell Casey, retired from the Army gave a great presentation. The take away there was "where are your electricians?" His point was that at the turn of the century in 1900, electricity was new. The government and large organizations had electricians on staff. When they needed new lines or a problem fixed, they just got their electricians to do it. Today, we simply expect to be about to flip a switch and for everything to work. If we need an electrician, we outsource it. His point was that security is moving in that direction. As things become more virtualized, more cloud based, organizations should shift to what they do best and leave the commoditization of infrastructure and security to professionals. But, he also restated the issue regarding the limited number of professionals on the market. His point here was was as the government continues to develop and employee many of those with these specialties, that as organizations start to wake up and truly understand how wide spread this issue truly is, that the shortage today could grow substantially before market forces can begin to correct the situation.



Now, I do not know if this was a one off event. I hope not. It was extremely well done. All the speakers were top notch from beginning to end. It has me rethinking our CIS programs at Tarleton to see how we might be able to collaborate with the CJ folks in order to generate some synergies. This was exciting, cool stuff.



Media Relations - Tarleton State University:



'via Blog this'

Wednesday, July 20, 2016

Security Theories

Computer Anxiety: "Excessive timidity in using computers, negative comments against computers and information science, attempts to reduce the amount of time spent using computers, and even the avoidance of using computersfrom the place where they are located" (Doronina, 1995).

  • Doronina, O. "Fear of Computers: Its Nature, Prevention and Cure," Russian Social Science Review (36:4) 1995, pp 79-90.


General Deterrence Theory:
  • BOSS SR, KIRSCH LJ, ANGERMEIER I, SHINGLER RA and BOSS RW (2009) If Someone Is Watching, I’ll Do What I’m Asked: Mandatoriness, Control, and Information Security. European Journal of Information Systems 18(2), 151–164. 
  • STRAUB DW and WELKE RJ (1998) Coping With Systems Risk: Security Planning Models for Management Decision Making. MIS Quarterly 22(4), 441–469.
  • D’ARCY J and HOVAV A (2009) Does One Size Fit All? Examining the Differential Effects of IS Security Countermeasures. Journal of Business Ethics 89, 59–71.
  • HERATH T and RAO HR (2009) Protection Motivation and Deterrence: A Framework for Security Policy Compliance in Organisations. European Journal of Information Systems 18(2), 106–125. 
  • PAHNILA S, SIPONEN M and MAHMOOD A (2007) Employees’ Behavior towards IS Security Policy Compliance. In: 40th Annual Hawaii International Conference on System Sciences. Waikoloa, HI: IEEE Computer Society.
  • STRAUB DW (1990) Effective IS Security: An Empirical Study. Information Systems Research 1(3), 255–276. 

Protection Motivation Theory:
  • Rogers, R.W. (1975). A protection motivation theory of fear appeals and attitude change. Journal of Psychology, 91, 93-114.
  • Rogers, R.W. (1983). Cognitive and physiological processes in fear appeals and attitude change: A revised theory of protection motivation. In J. Cacioppo & R. Petty (Eds.), Social psychophysiology (pp. 153-176). New York: Guilford.
  • MADDUX JE and ROGERS RW (1983) Protection Motivation and Self-Efficacy: A Revised Theory of Fear Appeals and Attitude Change. Journal of Experimental Social Psychology 19(5), 469– 479.
  • CROSSLER RE (2010) Protection Motivation Theory: Understanding Determinants to Backing Up Personal Data. In: 43rd Hawaii International Conference on System Sciences. pp. 1–10.
  • HERATH T and RAO HR (2009) Protection Motivation and Deterrence: A Framework for Security Policy Compliance in Organisations. European Journal of Information Systems 18(2), 106–125.
  • JOHNSTON AC and WARKENTIN M (2010) Fear Appeals and Information Security Behaviors: An Empirical Study. MIS Quarterly 34(3), 549–A4.
  • PAHNILA S, SIPONEN M and MAHMOOD A (2007) Employees’ Behavior towards IS Security Policy Compliance. In: 40th Annual Hawaii International Conference on System Sciences. Waikoloa, HI: IEEE Computer Society.
  • VANCE A, SIPONEN M and PAHNILA S (2012) Motivating IS Security Compliance: Insights from Habit and Protection Motivation Theory. Information & Management 49(3–4), 190–198.
  • WOON I, TAN G-W and LOW R (2005) A Protection Motivation Theory Approach to Home Wireless Security. In: Proceedings of the 26th International Conference on Information Systems. pp. 367–380.
  • LEE Y and LARSEN KR (2009) Threat or Coping Appraisal: Determinants of SMB Executives’ Decision to Adopt Anti-Malware Software. European Journal of Information Systems 18(2), 177–187. 
Neutralization Theory:


Technology Threat Avoidance Theory (TTAT): Posits that threat avoidance behavior functions as a dynamic positive feedback loop (concept derived from cybernetic theory, and general systems theory) composed of two cognitive processes, threat and coping appraisals, which determine how an individual would cope with IT threats.
  • LIANG H and XUE Y (2009) Avoidance of Information Technology Threats: A Theoretical Perspective. MIS Quarterly 33(1), 71–90.
  • LIANG H and XUE Y (2010) Understanding Security Behaviors in Personal Computer Usage: A Threat Avoidance Perspective. Journal of the Association for Information Systems 11(7), 394– 413. 
Fear Appeal Theory
  • JOHNSTON AC and WARKENTIN M (2010) Fear Appeals and Information Security
  • Behaviors: An Empirical Study. MIS Quarterly 34(3), 549–A4.
Technology Anxiety (As a predictor of technology adoption): An individual's tendency to be uneasy, aprehensive, or fearful about the current or future use of technology ((Parasuraman, et al,m 1990; Allen, 2002).
  • Allen, J.W., and Parikh, M.A. "The Impact of Personal Traits on IT Adoption," Proceedings of the 8th Americas Conference on Information Systems, Dallas, TX, USA, 2002.
  • Meuter, M.L., Ostrom, A.L., Bitner, M.J., and Rountree, R. "The Influence of Technology Anxiety on Consumer Use and Experiences with Self-Service Technologies," Journal of Business Research (56) 2003, pp 899-906.
  • Parasuraman, S., and Igbaria, M. "An Examination of Gender Differences in the Determinants of Computer Anxiety and Attitudes Towards Microcomputers Among Managers," International Journal of Man-Machine Studies (32:3) 1990, pp 327-340.

Security Theories

Computer Anxiety: "Excessive timidity in using computers, negative comments against computers and information science, attempts to reduce the amount of time spent using computers, and even the avoidance of using computersfrom the place where they are located" (Doronina, 1995).

  • Doronina, O. "Fear of Computers: Its Nature, Prevention and Cure," Russian Social Science Review (36:4) 1995, pp 79-90.


General Deterrence Theory:
  • BOSS SR, KIRSCH LJ, ANGERMEIER I, SHINGLER RA and BOSS RW (2009) If Someone Is Watching, I’ll Do What I’m Asked: Mandatoriness, Control, and Information Security. European Journal of Information Systems 18(2), 151–164. 
  • STRAUB DW and WELKE RJ (1998) Coping With Systems Risk: Security Planning Models for Management Decision Making. MIS Quarterly 22(4), 441–469.
  • D’ARCY J and HOVAV A (2009) Does One Size Fit All? Examining the Differential Effects of IS Security Countermeasures. Journal of Business Ethics 89, 59–71.
  • HERATH T and RAO HR (2009) Protection Motivation and Deterrence: A Framework for Security Policy Compliance in Organisations. European Journal of Information Systems 18(2), 106–125. 
  • PAHNILA S, SIPONEN M and MAHMOOD A (2007) Employees’ Behavior towards IS Security Policy Compliance. In: 40th Annual Hawaii International Conference on System Sciences. Waikoloa, HI: IEEE Computer Society.
  • STRAUB DW (1990) Effective IS Security: An Empirical Study. Information Systems Research 1(3), 255–276. 

Protection Motivation Theory:
  • Rogers, R.W. (1975). A protection motivation theory of fear appeals and attitude change. Journal of Psychology, 91, 93-114.
  • Rogers, R.W. (1983). Cognitive and physiological processes in fear appeals and attitude change: A revised theory of protection motivation. In J. Cacioppo & R. Petty (Eds.), Social psychophysiology (pp. 153-176). New York: Guilford.
  • MADDUX JE and ROGERS RW (1983) Protection Motivation and Self-Efficacy: A Revised Theory of Fear Appeals and Attitude Change. Journal of Experimental Social Psychology 19(5), 469– 479.
  • CROSSLER RE (2010) Protection Motivation Theory: Understanding Determinants to Backing Up Personal Data. In: 43rd Hawaii International Conference on System Sciences. pp. 1–10.
  • HERATH T and RAO HR (2009) Protection Motivation and Deterrence: A Framework for Security Policy Compliance in Organisations. European Journal of Information Systems 18(2), 106–125.
  • JOHNSTON AC and WARKENTIN M (2010) Fear Appeals and Information Security Behaviors: An Empirical Study. MIS Quarterly 34(3), 549–A4.
  • PAHNILA S, SIPONEN M and MAHMOOD A (2007) Employees’ Behavior towards IS Security Policy Compliance. In: 40th Annual Hawaii International Conference on System Sciences. Waikoloa, HI: IEEE Computer Society.
  • VANCE A, SIPONEN M and PAHNILA S (2012) Motivating IS Security Compliance: Insights from Habit and Protection Motivation Theory. Information & Management 49(3–4), 190–198.
  • WOON I, TAN G-W and LOW R (2005) A Protection Motivation Theory Approach to Home Wireless Security. In: Proceedings of the 26th International Conference on Information Systems. pp. 367–380.
  • LEE Y and LARSEN KR (2009) Threat or Coping Appraisal: Determinants of SMB Executives’ Decision to Adopt Anti-Malware Software. European Journal of Information Systems 18(2), 177–187. 
Neutralization Theory:


Technology Threat Avoidance Theory (TTAT): Posits that threat avoidance behavior functions as a dynamic positive feedback loop (concept derived from cybernetic theory, and general systems theory) composed of two cognitive processes, threat and coping appraisals, which determine how an individual would cope with IT threats.
  • LIANG H and XUE Y (2009) Avoidance of Information Technology Threats: A Theoretical Perspective. MIS Quarterly 33(1), 71–90.
  • LIANG H and XUE Y (2010) Understanding Security Behaviors in Personal Computer Usage: A Threat Avoidance Perspective. Journal of the Association for Information Systems 11(7), 394– 413. 
Fear Appeal Theory
  • JOHNSTON AC and WARKENTIN M (2010) Fear Appeals and Information Security
  • Behaviors: An Empirical Study. MIS Quarterly 34(3), 549–A4.
Technology Anxiety (As a predictor of technology adoption): An individual's tendency to be uneasy, aprehensive, or fearful about the current or future use of technology ((Parasuraman, et al,m 1990; Allen, 2002).
  • Allen, J.W., and Parikh, M.A. "The Impact of Personal Traits on IT Adoption," Proceedings of the 8th Americas Conference on Information Systems, Dallas, TX, USA, 2002.
  • Meuter, M.L., Ostrom, A.L., Bitner, M.J., and Rountree, R. "The Influence of Technology Anxiety on Consumer Use and Experiences with Self-Service Technologies," Journal of Business Research (56) 2003, pp 899-906.
  • Parasuraman, S., and Igbaria, M. "An Examination of Gender Differences in the Determinants of Computer Anxiety and Attitudes Towards Microcomputers Among Managers," International Journal of Man-Machine Studies (32:3) 1990, pp 327-340.

Security Theories

Computer Anxiety: "Excessive timidity in using computers, negative comments against computers and information science, attempts to reduce the amount of time spent using computers, and even the avoidance of using computersfrom the place where they are located" (Doronina, 1995).

  • Doronina, O. "Fear of Computers: Its Nature, Prevention and Cure," Russian Social Science Review (36:4) 1995, pp 79-90.


General Deterrence Theory:
  • BOSS SR, KIRSCH LJ, ANGERMEIER I, SHINGLER RA and BOSS RW (2009) If Someone Is Watching, I’ll Do What I’m Asked: Mandatoriness, Control, and Information Security. European Journal of Information Systems 18(2), 151–164. 
  • STRAUB DW and WELKE RJ (1998) Coping With Systems Risk: Security Planning Models for Management Decision Making. MIS Quarterly 22(4), 441–469.
  • D’ARCY J and HOVAV A (2009) Does One Size Fit All? Examining the Differential Effects of IS Security Countermeasures. Journal of Business Ethics 89, 59–71.
  • HERATH T and RAO HR (2009) Protection Motivation and Deterrence: A Framework for Security Policy Compliance in Organisations. European Journal of Information Systems 18(2), 106–125. 
  • PAHNILA S, SIPONEN M and MAHMOOD A (2007) Employees’ Behavior towards IS Security Policy Compliance. In: 40th Annual Hawaii International Conference on System Sciences. Waikoloa, HI: IEEE Computer Society.
  • STRAUB DW (1990) Effective IS Security: An Empirical Study. Information Systems Research 1(3), 255–276. 

Protection Motivation Theory:
  • Rogers, R.W. (1975). A protection motivation theory of fear appeals and attitude change. Journal of Psychology, 91, 93-114.
  • Rogers, R.W. (1983). Cognitive and physiological processes in fear appeals and attitude change: A revised theory of protection motivation. In J. Cacioppo & R. Petty (Eds.), Social psychophysiology (pp. 153-176). New York: Guilford.
  • MADDUX JE and ROGERS RW (1983) Protection Motivation and Self-Efficacy: A Revised Theory of Fear Appeals and Attitude Change. Journal of Experimental Social Psychology 19(5), 469– 479.
  • CROSSLER RE (2010) Protection Motivation Theory: Understanding Determinants to Backing Up Personal Data. In: 43rd Hawaii International Conference on System Sciences. pp. 1–10.
  • HERATH T and RAO HR (2009) Protection Motivation and Deterrence: A Framework for Security Policy Compliance in Organisations. European Journal of Information Systems 18(2), 106–125.
  • JOHNSTON AC and WARKENTIN M (2010) Fear Appeals and Information Security Behaviors: An Empirical Study. MIS Quarterly 34(3), 549–A4.
  • PAHNILA S, SIPONEN M and MAHMOOD A (2007) Employees’ Behavior towards IS Security Policy Compliance. In: 40th Annual Hawaii International Conference on System Sciences. Waikoloa, HI: IEEE Computer Society.
  • VANCE A, SIPONEN M and PAHNILA S (2012) Motivating IS Security Compliance: Insights from Habit and Protection Motivation Theory. Information & Management 49(3–4), 190–198.
  • WOON I, TAN G-W and LOW R (2005) A Protection Motivation Theory Approach to Home Wireless Security. In: Proceedings of the 26th International Conference on Information Systems. pp. 367–380.
  • LEE Y and LARSEN KR (2009) Threat or Coping Appraisal: Determinants of SMB Executives’ Decision to Adopt Anti-Malware Software. European Journal of Information Systems 18(2), 177–187. 
Neutralization Theory:


Technology Threat Avoidance Theory (TTAT): Posits that threat avoidance behavior functions as a dynamic positive feedback loop (concept derived from cybernetic theory, and general systems theory) composed of two cognitive processes, threat and coping appraisals, which determine how an individual would cope with IT threats.
  • LIANG H and XUE Y (2009) Avoidance of Information Technology Threats: A Theoretical Perspective. MIS Quarterly 33(1), 71–90.
  • LIANG H and XUE Y (2010) Understanding Security Behaviors in Personal Computer Usage: A Threat Avoidance Perspective. Journal of the Association for Information Systems 11(7), 394– 413. 
Fear Appeal Theory
  • JOHNSTON AC and WARKENTIN M (2010) Fear Appeals and Information Security
  • Behaviors: An Empirical Study. MIS Quarterly 34(3), 549–A4.
Technology Anxiety (As a predictor of technology adoption): An individual's tendency to be uneasy, aprehensive, or fearful about the current or future use of technology ((Parasuraman, et al,m 1990; Allen, 2002).
  • Allen, J.W., and Parikh, M.A. "The Impact of Personal Traits on IT Adoption," Proceedings of the 8th Americas Conference on Information Systems, Dallas, TX, USA, 2002.
  • Meuter, M.L., Ostrom, A.L., Bitner, M.J., and Rountree, R. "The Influence of Technology Anxiety on Consumer Use and Experiences with Self-Service Technologies," Journal of Business Research (56) 2003, pp 899-906.
  • Parasuraman, S., and Igbaria, M. "An Examination of Gender Differences in the Determinants of Computer Anxiety and Attitudes Towards Microcomputers Among Managers," International Journal of Man-Machine Studies (32:3) 1990, pp 327-340.