Tietoturvatietoisuus eduskunnassa

As digitalization has become more widespread, information systems have proliferated and the attacks against them have evolved into ever more com-plex forms. Human error remains one of the leading causes of security inci-dents, and in response organizations have begun to offer cybersecurity train-ing...

Full description

Bibliographic Details
Main Author: Järvinen, Sami
Other Authors: Informaatioteknologian tiedekunta, Faculty of Information Technology, Jyväskylän yliopisto, University of Jyväskylä
Format: Master's thesis
Language:fin
Published: 2025
Subjects:
Online Access: https://jyx.jyu.fi/handle/123456789/102949
_version_ 1834222500892901376
author Järvinen, Sami
author2 Informaatioteknologian tiedekunta Faculty of Information Technology Jyväskylän yliopisto University of Jyväskylä
author_facet Järvinen, Sami Informaatioteknologian tiedekunta Faculty of Information Technology Jyväskylän yliopisto University of Jyväskylä Järvinen, Sami Informaatioteknologian tiedekunta Faculty of Information Technology Jyväskylän yliopisto University of Jyväskylä
author_sort Järvinen, Sami
datasource_str_mv jyx
description As digitalization has become more widespread, information systems have proliferated and the attacks against them have evolved into ever more com-plex forms. Human error remains one of the leading causes of security inci-dents, and in response organizations have begun to offer cybersecurity train-ing to their staff to reduce vulnerabilities. Effective training has been shown to have a significant impact on the prevailing security behavior within an organ-ization. An individual’s cybersecurity awareness serves as a useful measura-ble construct because it encompasses one’s attitudes, behaviors, and knowledge of security issues in accordance with the KAB model. By measur-ing security awareness, an organization can assess its personnel’s readiness to confront security challenges as well as their attitudes toward existing policies. Awareness metrics also reveal specific areas that may require additional train-ing or resources. In this study, we measured the cybersecurity awareness of Finland’s parliament and associated agencies using a quantitative online ques-tionnaire. The purpose was to assess the current state of staff information se-curity awareness and to identify topic areas that require more attention in training. Awareness was measured based on the KAB model by assessing re-spondents’ information security knowledge, information security behavior and information security attitude. The survey responses were given using a 5-point Likert scale. The results indicate that respondents display strong overall security awareness, with no critical deficiencies identified. However, the data also highlights a few weaker areas that can now be targeted for improvement in the future training and resource allocation. Digitalisaation yleistyessä tietojärjestelmät ovat yleistyneet ja niihin kohdis-tuvat hyökkäykset ovat kehittyneet jatkuvasti monimutkaisemmiksi. Ihmisen tekemä erhe on yksi yleisimmistä syistä tietoturvahäiriöihin ja tämän myötä organisaatiot ovat alkaneet tarjota tietoturvakoulutusta henkilöstölleen haa-voittuvuuksien vähentämiseksi. Toimivalla koulutuksella on todettu olevan merkittävä vaikutus organisaatiossa vallitsevaan tietoturvakäyttäytymiseen. Henkilön tietoturvatietoisuus toimii hyvänä mitattavana kohteena, koska se kattaa henkilön asenteen, käytöksen ja tiedot tietoturva-asioissa KAB-mallin mukaisesti. Tietoturvatietoisuutta mittaamalla voidaan arvioida henkilöstön valmiuksia kohdata tietoturvaongelmia ja asenteita, esimerkiksi voimassa ole-via käytäntöjä kohtaan. Tietoisuuden kautta voidaan havainnoida, onko ole-massa joitakin osa-alueita, jotka tarvitsevat lisää huomiota koulutuksen tai resurssien avulla. Tutkielmassa mitattiin eduskunnan ja sen rinnalla toimivien virastojen tietoturvatietoisuutta verkkopohjaisella kvantitatiivisella kyselylo-makkeella. Tarkoituksena oli kartoittaa henkilöstön tietoturvatietoisuuden nykytilaa ja havaita aihealueita, jotka vaativat lisää huomiota koulutuksessa. Tietoisuutta mitattiin KAB-malliin perustuen ja arvioiden vastaajien tietotur-vatietoja, tietoturvakäyttäytymistä ja tietoturva-asennetta. Kyselyyn vastattiin kysymyksiin 5-portaisella Likertin-asteikolla. Tuloksista paljastuu vastaajien vahva tietoturvatietoisuus, eikä kriittisiä puutteita ollut. Tuloksista kuitenkin voidaan nähdä hieman heikompia osa-alueita, johon voidaan nyt kiinnittää huomiota tulevaisuudessa niiden parantamiseksi.
first_indexed 2025-06-02T20:00:55Z
format Pro gradu
fullrecord [{"key": "dc.contributor.advisor", "value": "Pekkola, Samuli", "language": null, "element": "contributor", "qualifier": "advisor", "schema": "dc"}, {"key": "dc.contributor.author", "value": "J\u00e4rvinen, Sami", "language": null, "element": "contributor", "qualifier": "author", "schema": "dc"}, {"key": "dc.date.accessioned", "value": "2025-06-02T11:47:17Z", "language": null, "element": "date", "qualifier": "accessioned", "schema": "dc"}, {"key": "dc.date.available", "value": "2025-06-02T11:47:17Z", "language": null, "element": "date", "qualifier": "available", "schema": "dc"}, {"key": "dc.date.issued", "value": "2025", "language": null, "element": "date", "qualifier": "issued", "schema": "dc"}, {"key": "dc.identifier.uri", "value": "https://jyx.jyu.fi/handle/123456789/102949", "language": null, "element": "identifier", "qualifier": "uri", "schema": "dc"}, {"key": "dc.description.abstract", "value": "As digitalization has become more widespread, information systems have proliferated and the attacks against them have evolved into ever more com-plex forms. Human error remains one of the leading causes of security inci-dents, and in response organizations have begun to offer cybersecurity train-ing to their staff to reduce vulnerabilities. Effective training has been shown to have a significant impact on the prevailing security behavior within an organ-ization. An individual\u2019s cybersecurity awareness serves as a useful measura-ble construct because it encompasses one\u2019s attitudes, behaviors, and knowledge of security issues in accordance with the KAB model. By measur-ing security awareness, an organization can assess its personnel\u2019s readiness to confront security challenges as well as their attitudes toward existing policies. Awareness metrics also reveal specific areas that may require additional train-ing or resources. In this study, we measured the cybersecurity awareness of Finland\u2019s parliament and associated agencies using a quantitative online ques-tionnaire. The purpose was to assess the current state of staff information se-curity awareness and to identify topic areas that require more attention in training. Awareness was measured based on the KAB model by assessing re-spondents\u2019 information security knowledge, information security behavior and information security attitude. The survey responses were given using a 5-point Likert scale. The results indicate that respondents display strong overall security awareness, with no critical deficiencies identified. However, the data also highlights a few weaker areas that can now be targeted for improvement in the future training and resource allocation.", "language": "en", "element": "description", "qualifier": "abstract", "schema": "dc"}, {"key": "dc.description.abstract", "value": "Digitalisaation yleistyess\u00e4 tietoj\u00e4rjestelm\u00e4t ovat yleistyneet ja niihin kohdis-tuvat hy\u00f6kk\u00e4ykset ovat kehittyneet jatkuvasti monimutkaisemmiksi. Ihmisen tekem\u00e4 erhe on yksi yleisimmist\u00e4 syist\u00e4 tietoturvah\u00e4iri\u00f6ihin ja t\u00e4m\u00e4n my\u00f6t\u00e4 organisaatiot ovat alkaneet tarjota tietoturvakoulutusta henkil\u00f6st\u00f6lleen haa-voittuvuuksien v\u00e4hent\u00e4miseksi. Toimivalla koulutuksella on todettu olevan merkitt\u00e4v\u00e4 vaikutus organisaatiossa vallitsevaan tietoturvak\u00e4ytt\u00e4ytymiseen. Henkil\u00f6n tietoturvatietoisuus toimii hyv\u00e4n\u00e4 mitattavana kohteena, koska se kattaa henkil\u00f6n asenteen, k\u00e4yt\u00f6ksen ja tiedot tietoturva-asioissa KAB-mallin mukaisesti. Tietoturvatietoisuutta mittaamalla voidaan arvioida henkil\u00f6st\u00f6n valmiuksia kohdata tietoturvaongelmia ja asenteita, esimerkiksi voimassa ole-via k\u00e4yt\u00e4nt\u00f6j\u00e4 kohtaan. Tietoisuuden kautta voidaan havainnoida, onko ole-massa joitakin osa-alueita, jotka tarvitsevat lis\u00e4\u00e4 huomiota koulutuksen tai resurssien avulla. Tutkielmassa mitattiin eduskunnan ja sen rinnalla toimivien virastojen tietoturvatietoisuutta verkkopohjaisella kvantitatiivisella kyselylo-makkeella. Tarkoituksena oli kartoittaa henkil\u00f6st\u00f6n tietoturvatietoisuuden nykytilaa ja havaita aihealueita, jotka vaativat lis\u00e4\u00e4 huomiota koulutuksessa. Tietoisuutta mitattiin KAB-malliin perustuen ja arvioiden vastaajien tietotur-vatietoja, tietoturvak\u00e4ytt\u00e4ytymist\u00e4 ja tietoturva-asennetta. Kyselyyn vastattiin kysymyksiin 5-portaisella Likertin-asteikolla. Tuloksista paljastuu vastaajien vahva tietoturvatietoisuus, eik\u00e4 kriittisi\u00e4 puutteita ollut. Tuloksista kuitenkin voidaan n\u00e4hd\u00e4 hieman heikompia osa-alueita, johon voidaan nyt kiinnitt\u00e4\u00e4 huomiota tulevaisuudessa niiden parantamiseksi.", "language": "fi", "element": "description", "qualifier": "abstract", "schema": "dc"}, {"key": "dc.description.provenance", "value": "Submitted by jyx lomake-julkaisija (jyx-julkaisija.group@korppi.jyu.fi) on 2025-06-02T11:47:17Z\nNo. of bitstreams: 0", "language": "en", "element": "description", "qualifier": "provenance", "schema": "dc"}, {"key": "dc.description.provenance", "value": "Made available in DSpace on 2025-06-02T11:47:17Z (GMT). No. of bitstreams: 0", "language": "en", "element": "description", "qualifier": "provenance", "schema": "dc"}, {"key": "dc.format.extent", "value": "74", "language": null, "element": "format", "qualifier": "extent", "schema": "dc"}, {"key": "dc.format.mimetype", "value": "application/pdf", "language": null, "element": "format", "qualifier": "mimetype", "schema": "dc"}, {"key": "dc.language.iso", "value": "fin", "language": null, "element": "language", "qualifier": "iso", "schema": "dc"}, {"key": "dc.rights", "value": "In Copyright", "language": null, "element": "rights", "qualifier": null, "schema": "dc"}, {"key": "dc.title", "value": "Tietoturvatietoisuus eduskunnassa", "language": null, "element": "title", "qualifier": null, "schema": "dc"}, {"key": "dc.type", "value": "master thesis", "language": null, "element": "type", "qualifier": null, "schema": "dc"}, {"key": "dc.identifier.urn", "value": "URN:NBN:fi:jyu-202506024758", "language": null, "element": "identifier", "qualifier": "urn", "schema": "dc"}, {"key": "dc.contributor.faculty", "value": "Informaatioteknologian tiedekunta", "language": "fi", "element": "contributor", "qualifier": "faculty", "schema": "dc"}, {"key": "dc.contributor.faculty", "value": "Faculty of Information Technology", "language": "en", "element": "contributor", "qualifier": "faculty", "schema": "dc"}, {"key": "dc.contributor.organization", "value": "Jyv\u00e4skyl\u00e4n yliopisto", "language": "fi", "element": "contributor", "qualifier": "organization", "schema": "dc"}, {"key": "dc.contributor.organization", "value": "University of Jyv\u00e4skyl\u00e4", "language": "en", "element": "contributor", "qualifier": "organization", "schema": "dc"}, {"key": "dc.subject.discipline", "value": "Kyberturvallisuuden maisteriohjelma", "language": "fi", "element": "subject", "qualifier": "discipline", "schema": "dc"}, {"key": "dc.subject.discipline", "value": "Master's Degree Programme in Cyber Security", "language": "en", "element": "subject", "qualifier": "discipline", "schema": "dc"}, {"key": "dc.type.coar", "value": "http://purl.org/coar/resource_type/c_bdcc", "language": null, "element": "type", "qualifier": "coar", "schema": "dc"}, {"key": "dc.rights.copyright", "value": "\u00a9 The Author(s)", "language": null, "element": "rights", "qualifier": "copyright", "schema": "dc"}, {"key": "dc.rights.accesslevel", "value": "restrictedAccess", "language": null, "element": "rights", "qualifier": "accesslevel", "schema": "dc"}, {"key": "dc.type.publication", "value": "masterThesis", "language": null, "element": "type", "qualifier": "publication", "schema": "dc"}, {"key": "dc.format.content", "value": "fulltext", "language": null, "element": "format", "qualifier": "content", "schema": "dc"}, {"key": "dc.rights.url", "value": "https://rightsstatements.org/page/InC/1.0/", "language": null, "element": "rights", "qualifier": "url", "schema": "dc"}, {"key": "dc.rights.accessrights", "value": "Tekij\u00e4 ei ole antanut lupaa avoimeen julkaisuun, joten aineisto on luettavissa vain Jyv\u00e4skyl\u00e4n yliopiston kirjaston arkistoty\u00f6semalta. Ks. https://www.jyu.fi/fi/osc/kirjasto/tyoskentelytilat/laitteet-ja-tilat#toc-jyx-ty-asema.", "language": "fi", "element": "rights", "qualifier": "accessrights", "schema": "dc"}, {"key": "dc.rights.accessrights", "value": "The author has not given permission to make the work publicly available electronically. Therefore the material can be read only at the archival workstation at Jyv\u00e4skyl\u00e4 University Library (https://www.jyu.fi/en/osc/library/workspaces/facilities-and-equipment#toc-jyx-workstation).", "language": "en", "element": "rights", "qualifier": "accessrights", "schema": "dc"}, {"key": "dc.description.accessibilityfeature", "value": "ei tietoa saavutettavuudesta", "language": "fi", "element": "description", "qualifier": "accessibilityfeature", "schema": "dc"}, {"key": "dc.description.accessibilityfeature", "value": "unknown accessibility", "language": "en", "element": "description", "qualifier": "accessibilityfeature", "schema": "dc"}]
id jyx.123456789_102949
language fin
last_indexed 2025-06-02T20:03:19Z
main_date 2025-01-01T00:00:00Z
main_date_str 2025
publishDate 2025
record_format qdc
source_str_mv jyx
spellingShingle Järvinen, Sami Tietoturvatietoisuus eduskunnassa Kyberturvallisuuden maisteriohjelma Master's Degree Programme in Cyber Security
title Tietoturvatietoisuus eduskunnassa
title_full Tietoturvatietoisuus eduskunnassa
title_fullStr Tietoturvatietoisuus eduskunnassa Tietoturvatietoisuus eduskunnassa
title_full_unstemmed Tietoturvatietoisuus eduskunnassa Tietoturvatietoisuus eduskunnassa
title_short Tietoturvatietoisuus eduskunnassa
title_sort tietoturvatietoisuus eduskunnassa
title_txtP Tietoturvatietoisuus eduskunnassa
topic Kyberturvallisuuden maisteriohjelma Master's Degree Programme in Cyber Security
topic_facet Kyberturvallisuuden maisteriohjelma Master's Degree Programme in Cyber Security
url https://jyx.jyu.fi/handle/123456789/102949 http://www.urn.fi/URN:NBN:fi:jyu-202506024758
work_keys_str_mv AT järvinensami tietoturvatietoisuuseduskunnassa