References
Adebayo, A.O. (2022). Leveraging threat intelligence in DevSecOps for banking security, International Journal of Scientific Research and Modern Technology, 1(1), pp. 1–14. Adebayo, A., Afuwape, A.A., Akindemowo, A.O., Erigha, E.D., Obuse, E., Ajayi, J.O., and Soneye, O.M. (2023). A conceptual model for secure DevOps architecture using Jenkins, Terraform, and Kubernetes, International Journal of Multidisciplinary Research and Growth Evaluation, 4(1), pp. 245–263. https://doi.org/10.54660/.IJMRGE.2023.4.1. Albrechtsen, E. and Hovden, J. (2010). Improving information security awareness and behaviour through dialogue, participation, and collective reflection. An intervention study, Computers & Security, 29(4), pp. 432–445. https://doi.org/10.1016/j.cose.2009.12.005. Aldawood, H. and Skinner, G. (2019). Reviewing cyber security social engineering training and awareness programs—pitfalls and ongoing issues, Future Internet, 11(3), p. 73. https://doi.org/10.3390/fi11030073. AlHogail, A. (2015). Design and validation of information security culture framework, Computers in Human Behavior, 49, pp. 567–575. https://doi.org/10.1016/j.chb.2015.03.054. Anderson, C.L. and Agarwal, R. (2010). Practicing safe computing: a multimethod empirical examination of home computer user security behavioral intentions, MIS Quarterly, 34(3), pp. 613–643. Available at: https://doi.org/10.2307/25750694. Aurigemma, S. and Mattson, T. (2017). Privilege or procedure: evaluating the effect of employee status on intent to comply with socially interactive information security threats and controls, Computers & Security, 66, pp. 218–234. https://doi.org/10.1016/j.cose.2017.02.006. Babatope, O.M., Oyewole, T., Ogbole, J.I., and Okoruwa, P.O. (2023). Developing an AI-based incident response automation framework to minimize downtime in IT service operations, International Journal of Advanced Multidisciplinary Research and Studies, 3(6), pp. 1– 14. Bada, M., Sasse, A.M. and Nurse, J.R.C. (2019). Cyber security awareness campaigns: why do they fail to change behaviour?', International Conference on Cyber Security for Sustainable Society, pp. 118–131. Beautement, A., Sasse, M.A., and Wonham, M. (2008). The compliance budget: managing security behaviour in organisations, in Proceedings of the 2008 New Security Paradigms Workshop. New York: ACM, pp. 47–58. https://doi.org/10.1145/1595676.1595684. Bongiovanni, I. (2019). The least secure places in the universe? A systematic literature review on information security management in higher education, Computers & Security, 86, pp. 350–357. https://doi.org/10.1016/j.cose.2019.07.003. Boss, S.R., Galletta, D.F., Lowry, P.B., Moody, G.D., and Polak, P. (2015). What do systems users have to fear? Using fear appeals to engender threats and fear that motivate protective security behaviors, MIS Quarterly, 39(4), pp. 837–864. https://doi.org/10.25300/MISQ/2015/39.4.5. Bukhari, T.T., Moyo, T.M., Tafirenyika, S., Taiwo, A.E., Tuboalabo, A. and Ajayi, A.E. (2022) 'AI-driven cybersecurity intelligence dashboards for threat prevention and forensics in regulated business sectors', International Journal of Multidisciplinary Education and Research, 3(2), pp. 1–11. Bulgurcu, B., Cavusoglu, H. and Benbasat, I. (2010). Information security policy compliance: an empirical study of rationality-based beliefs and information security awareness, MIS P-ISSN 2695- 1924 Quarterly, 34(3), pp. 523–548. https://doi.org/10.2307/25750690. Burns, A.J., Posey, C., Roberts, T.L., and Lowry, P.B. (2017). Examining the relationship of organizational insiders' psychological capital with information security threat and coping appraisals, Computers in Human Behavior, 68, pp. 190–209. https://doi.org/10.1016/j.chb.2016.11.018. Cappelli, D.M., Moore, A.P., and Trzeciak, R.F. (2012). The CERT guide to insider threats: how to prevent, detect, and respond to information technology crimes (theft, sabotage, fraud). Upper Saddle River, NJ: Addison-Wesley. Choi, M., Levy, Y., and Hovav, A. (2013). The role of user computer self-efficacy, cybersecurity countermeasures awareness, and cybersecurity skills toward computer misuse intention at government agencies, Journal of Information Privacy and Security, 9(2), pp. 49–72. Colwill, C. (2009). Human factors in information security: the insider threat – who can you trust these days?', Information Security Technical Report, 14(4), pp. 186–196. https://doi.org/10.1016/j.istr.2010.04.004. Cox, J. (2012). Information systems user security: a structured model of the knowing–doing gap, Computers in Human Behavior, 28(5), pp. 1849–1858. Available at: https://doi.org/10.1016/j.chb.2012.05.003. Cram, W.A., D'Arcy, J., and Proudfoot, J.G. (2019). Seeing the forest and the trees: a meta- analysis of the antecedents to information security policy compliance, MIS Quarterly, 43(2), pp. 525–554. Crossler, R.E., Johnston, A.C., Lowry, P.B., Hu, Q., Warkentin, M., and Baskerville, R. (2013). Future directions for behavioral information security research, Computers & Security, 32, pp. 90–101. https://doi.org/10.1016/j.cose.2012.09.010. Da Veiga, A. and Eloff, J.H.P. (2010). A framework and assessment instrument for information security culture, Computers & Security, 29(2), pp. 196–207. https://doi.org/10.1016/j.cose.2009.09.002. D'Arcy, J., Hovav, A. and Galletta, D. (2009). User awareness of security countermeasures and its impact on information systems misuse: a deterrence approach, Information Systems Research, 20(1), pp. 79–98. https://doi.org/10.1287/isre.1070.0160. Diaz, A., Sherman, A.T., and Joshi, A. (2020). Phishing in an academic community: a study of user susceptibility and behavior, Cryptologia, 44(1), pp. 53–67. https://doi.org/10.1080/01611194.2019.1623343. Egelman, S. and Peer, E. (2015). Scaling the security wall: developing a security behavior intentions scale , in Proceedings of the 33rd Annual ACM Conference on Human Factors in Computing Systems. New York: ACM, pp. 2873–2882. https://doi.org/10.1145/2702123.2702249. Essien, I.A., Adebayo, A.O., Afuwape, A.A., Eboseremen, B.O., Oladega, F., and Soneye, O.M. (2023). The ethics of web scraping in research: investigating the boundaries, legal implications, and societal acceptance of web scraping as a data collection method, Journal of Frontiers in Multidisciplinary Research, 4(1), pp. 529–538. https://doi.org/10.54660/.JFMR.2023.4.1.529-538. Furnell, S. and Vasileiou, I. (2017). Security education and awareness: just let them burn?', Network Security, 2017(12), pp. 5–9. https://doi.org/10.1016/S1353-4858(17)30122-8. Greitzer, F.L., Strozer, J.R., Cohen, S., Moore, A.P., Mundie, D., and Cowley, J. (2014). Analysis of unintentional insider threats deriving from social engineering exploits, in 2014 IEEE Security and Privacy Workshops. Piscataway: IEEE, pp. 236–250. P-ISSN 2695- 1924 https://doi.org/10.1109/SPW.2014.39. Hadlington, L. (2017). Human factors in cybersecurity: examining the link between Internet addiction, impulsivity, attitudes towards cybersecurity, and risky cybersecurity behaviours, Heliyon, 3(7), p. e00346. https://doi.org/10.1016/j.heliyon.2017.e00346. He, W. and Zhang, Z. (2019). Enterprise cybersecurity training and awareness programs: recommendations for success, Journal of Organizational Computing and Electronic Commerce, 29(4), pp. 249–257. https://doi.org/10.1080/10919392.2019.1611528. Herath, T. and Rao, H.R. (2009). Encouraging information security behaviors in organizations: role of penalties, pressures, and perceived effectiveness, Decision Support Systems, 47(2), pp. 154–165. https://doi.org/10.1016/j.dss.2009.02.005. Hu, Q., Dinev, T., Hart, P., and Cooke, D. (2012). Managing employee compliance with information security policies: the critical role of top management and organizational culture, Decision Sciences, 43(4), pp. 615–660. https://doi.org/10.1111/j.1540- 5915.2012.00361.x. Ifinedo, P. (2012). Understanding information systems security policy compliance: an integration of the theory of planned behavior and the protection motivation theory, Computers & Security, 31(1), pp. 83–95. https://doi.org/10.1016/j.cose.2011.10.007. Johnston, A.C., Warkentin, M., and Siponen, M. (2015). An enhanced fear appeal rhetorical framework: leveraging threats to the human asset through sanctioning rhetoric, MIS Quarterly, 39(1), pp. 113–134. Karjalainen, M. and Siponen, M. (2011). Toward a new meta-theory for designing information systems (IS) security training approaches, Journal of the Association for Information Systems, 12(8), pp. 518–555. https://doi.org/10.17705/1jais.00274. Karjalainen, M., Sarker, S. and Siponen, M. (2019). Toward a theory of information systems security behaviors of organizational employees: a dialectical process perspective, Information Systems Research, 30(2), pp. 687–704. https://doi.org/10.1287/isre.2018.0827. Khan, N.F., Ikram, N., Murugesan, S. and Akhunzada, A. (2020). Cyber-security and risky behaviors in a developing country context: a Pakistani perspective', Security Journal, 34, pp. 1–33. https://doi.org/10.1057/s41284-022-00343-4. Ki-Aries, D. and Faily, S. (2017). Persona-centred information security awareness', Computers & Security, 70, pp. 663–674. https://doi.org/10.1016/j.cose.2017.08.001. Lebek, B., Uffen, J., Neumann, M., Hohler, B. and Breitner, M.H. (2014). Information security awareness and behavior: a theory-based literature review, Management Research Review, 37(12), pp. 1049–1092. https://doi.org/10.1108/MRR-04-2013-0085. Liang, H. and Xue, Y. (2010). Understanding security behaviors in personal computer usage: a threat avoidance perspective, Journal of the Association for Information Systems, 11(7), pp. 394–413. https://doi.org/10.17705/1jais.00232. Liginlal, D., Sim, I., and Khansa, L. (2009). How significant is human error as a cause of privacy breaches? An empirical study and a framework for error management, Computers & Security, 28(3–4), pp. 215–228. https://doi.org/10.1016/j.cose.2008.11.003. Maasberg, M., Warren, J., and Beebe, N.L. (2015). The dark side of the insider: detecting the insider threat through examination of dark triad personality traits, in 2015, 48th Hawaii International Conference on System Sciences. Piscataway: IEEE, pp. 3518–3526. https://doi.org/10.1109/HICSS.2015.423. McCormac, A., Zwaans, T., Parsons, K., Calic, D., Butavicius, M., and Pattinson, M. (2017). P-ISSN 2695- 1924 Individual differences and information security awareness, Computers in Human Behavior, 69, pp. 151–156. https://doi.org/10.1016/j.chb.2016.11.065. Moyo, T.M., Tafirenyika, S., Tuboalabo, A., Taiwo, A.E., Bukhari, T.T., and Ajayi, A.E. (2023). Cloud-based knowledge management systems with AI-enhanced compliance and data privacy safeguards, International Journal of Multidisciplinary Futuristic Development, 4(2), pp. 67–77. https://doi.org/10.54660/IJMFD.2023.4.2.67-77. Moyo, T.M., Tafirenyika, S., Tuboalabo, A., Taiwo, A.E., Bukhari, T.T., and Ajayi, A.E. (2024). Continuous access governance strategies using AI for real-time security monitoring and adaptive privilege management, International Journal of Multidisciplinary Futuristic Development, 5(1), pp. 1–15. Nurse, J.R.C., Buckley, O., Legg, P.A., Goldsmith, M., Creese, S., Wright, G.R.T. and Whitty, M. (2014). Understanding insider threat: a framework for characterising attacks, in 2014 IEEE Security and Privacy Workshops. Piscataway: IEEE, pp. 214–228. https://doi.org/10.1109/SPW.2014.38. Obuse, E., Akindemowo, A.O., Ajayi, J.O., Erigha, E.D., Adebayo, A., and Afuwape, A.A. (2024). A conceptual framework for CI/CD pipeline security controls in hybrid application deployments, International Journal of Future Engineering Innovations, 1(2), pp. 25–47. https://doi.org/10.54660/IJFEI.2024.1.2.25-47. Okoruwa, P.O. (2023). An artificial intelligence-driven financial crime investigation framework for analyst decision support, International Journal of Advanced Multidisciplinary Research and Studies, 3(6), pp. 1–15. Okoruwa, P.O., Babatope, O.M., Mayo, W., and Adedayo, D. (2023). Designing a secure hybrid cloud management model for enterprise resource optimization and data protection, International Journal of Advanced Multidisciplinary Research and Studies, 3(6), pp. 1– 14. Padayachee, K. (2012) 'Taxonomy of compliant information security behavior', Computers & Security, 31(5), pp. 673–680. https://doi.org/10.1016/j.cose.2012.04.004. Pahnila, S., Siponen, M. and Mahmood, A. (2007). Employees' behavior towards IS security policy compliance, in 2007, 40th Annual Hawaii International Conference on System Sciences. Piscataway: IEEE, pp. 156b–156b. https://doi.org/10.1109/HICSS.2007.206. Parsons, K., McCormac, A., Butavicius, M., Pattinson, M. and Jerram, C. (2014). Determining employee awareness using the Human Aspects of Information Security Questionnaire (HAIS-Q), Computers & Security, 42, pp. 165–176. https://doi.org/10.1016/j.cose.2013.12.003. Parsons, K., Calic, D., Pattinson, M., Butavicius, M., McCormac, A., and Zwaans, T. (2017). The Human Aspects of Information Security Questionnaire (HAIS-Q): two further validation studies, Computers & Security, 66, pp. 40–51. https://doi.org/10.1016/j.cose.2017.01.004. Pfleeger, S.L. and Caputo, D.D. (2012). Leveraging behavioral science to mitigate cybersecurity risk, Computers & Security, 31(4), pp. 597–611. https://doi.org/10.1016/j.cose.2011.12.010. Posey, C., Roberts, T.L., and Lowry, P.B. (2015). The impact of organizational commitment on insiders' motivation to protect organizational information assets, Journal of Management Information Systems, 32(4), pp. 179–214. https://doi.org/10.1080/07421222.2015.1138374. Predd, J., Pfleeger, S.L., Hunker, J., and Bulford, C. (2008). Insiders behaving badly', IEEE P-ISSN 2695- 1924 Security & Privacy, 6(4), pp. 66–70. https://doi.org/10.1109/MSP.2008.87. Reeves, A., Delfabbro, P. and Calic, D. (2021). Encouraging employee engagement with cybersecurity: how to tackle cyber fatigue, SAGE Open, 11(1), pp. 1–11. https://doi.org/10.1177/21582440211000049. Renaud, K., Flowerday, S., Warkentin, M., Cockshott, P., and Orgeron, C. (2018). Is the responsibilization of the cyber security risk reasonable and judicious?', Computers & Security, 78, pp. 198–211. https://doi.org/10.1016/j.cose.2018.06.006. Safa, N.S., Von Solms, R. and Furnell, S. (2016). Information security policy compliance model in organizations, Computers & Security, 56, pp. 70–82. https://doi.org/10.1016/j.cose.2015.10.006. Safa, N.S., Maple, C., Furnell, S., Azad, M.A., Perera, C., Dabbagh, M., and Sookhak, M. (2019). Deterrence and prevention-based model to mitigate information security insider threats in organisations, Future Generation Computer Systems, 97, pp. 587–597. https://doi.org/10.1016/j.future.2019.03.024. Sasse, M.A., Brostoff, S. and Weirich, D. (2001). Transforming the 'weakest link' — a human/computer interaction approach to usable and effective security, BT Technology Journal, 19(3), pp. 122–131. https://doi.org/10.1023/A:1011902718709. Schultz, E.E. (2002). A framework for understanding and predicting insider attacks, Computers & Security, 21(6), pp. 526–531. https://doi.org/10.1016/S0167-4048(02)01009-X. Shaw, E.D. and Stock, H.V. (2011).Behavioral risk indicators of malicious insider theft of intellectual property: misreading the writing on the wall. Mountain View, CA: Symantec Corporation. Shittu, I.S.O.M.A., Adeniji, I.O., and Shittu, H. (2022). Blockchain-assisted secure data exchange architectures for SCADA-controlled power systems, IRE Journal, 6(3), pp. 21– 36. Silic, M. and Lowry, P.B. (2020). Using design-science-based gamification to improve organizational security training and compliance, Journal of Management Information Systems, 37(1), pp. 129–161. https://doi.org/10.1080/07421222.2019.1705512. Siponen, M. and Vance, A. (2010). Neutralization: new insights into the problem of employee information systems security policy violations, MIS Quarterly, 34(3), pp. 487–502. https://doi.org/10.2307/25750688. Sommestad, T., Karlzén, H. and Hallberg, J. (2015). The sufficiency of the theory of planned behavior for explaining information security policy compliance, Information & Computer Security, 23(2), pp. 200–217. https://doi.org/10.1108/ICS-04-2014-0025. Stanton, J.M., Stam, K.R., Mastrangelo, P., and Jolton, J. (2005). Analysis of end user security behaviors, Computers & Security, 24(2), pp. 124–133. https://doi.org/10.1016/j.cose.2004.07.001. Tsohou, A., Karyda, M., Kokolakis, S. and Kiountouzis, E. (2012). Analyzing trajectories of information security awareness, Information Technology & People, 25(3), pp. 327–352. https://doi.org/10.1108/09593841211254358. Tsohou, A., Karyda, M. and Kokolakis, S. (2015). Analyzing the role of cognitive and cultural biases in the internalization of information security policies: recommendations for information security awareness programs, Computers & Security, 52, pp. 128–141. https://doi.org/10.1016/j.cose.2015.04.006. Vance, A., Siponen, M. and Pahnila, S. (2012). Motivating IS security compliance: insights from habit and protection motivation theory', Information & Management, 49(3–4), pp. 190– P-ISSN 2695- 1924 198. https://doi.org/10.1016/j.im.2012.04.002. Vroom, C. and Von Solms, R. (2004). Towards information security behavioural compliance, Computers & Security, 23(3), pp. 191–198. https://doi.org/10.1016/j.cose.2004.01.012. Whitman, M.E. (2003). Enemy at the gate: threats to information security, Communications of the ACM, 46(8), pp. 91–95. https://doi.org/10.1145/859670.859675. Willison, R. and Warkentin, M. (2013). Beyond deterrence: an expanded view of employee computer abuse, MIS Quarterly, 37(1), pp. 1–20. Workman, M., Bommer, W.H., and Straub, D. (2008). Security lapses and the omission of information security measures: a threat control model and empirical test', Computers in Human Behavior, 24(6), pp. 2799–2816. https://doi.org/10.1016/j.chb.2008.04.005. Workman, M. (2008). Wisecrackers: a theory-grounded investigation of phishing and pretext social engineering threats to information security, Journal of the American Society for Information Science and Technology, 59(4), pp. 662–674. https://doi.org/10.1002/asi.20779. Yoo, C.W., Sanders, G.L., and Cerveny, R.P. (2018). Exploring the influence of flow and psychological ownership on security education, training, and awareness effectiveness and security compliance, Decision Support Systems, 108, pp. 107–118. https://doi.org/10.1016/j.dss.2018.02.009. Zhuwankinyu, E.K., Moyo, T.M., and Mupa, M. (2024). Leveraging generative AI for an ethical and adaptive cybersecurity framework in enterprise environments, IRE Journals, 8(6), pp. 654–675.