Self-Efficacy and Security Behavior: Results from a Systematic Review of Research Methods

Privacy Perception & Decision-MakingCybersecurity Training & AwarenessCybersecurity EngineersPrivacy Policy Makers

Title of the Paper

Self-Efficacy and Security Behavior: Results from a Systematic Review of Research Methods

Paper Information

  • Subject Area: Cybersecurity, Psychology, and User Behavior
  • Keywords: Self-efficacy, Cybersecurity, Systematic review, Research methods, Security behavior, Psychometrics

Research Background and Issues

  • Issues or Challenges:

    • The psychological foundation of cybersecurity behavior has yet to be standardized, particularly in the measurement and theoretical mechanisms of "self-efficacy."
    • Inconsistent definitions and methods in existing literature lead to fragmented data and difficulties in reproducing research findings.
  • Importance of the Research:

    • Data privacy and IT security have become key public concerns, and the formation of secure habits lies at the intersection of technology and psychology.
    • Self-efficacy is considered the only psychological variable that significantly predicts cybersecurity behavior, making it crucial to study its role and operational potential.
  • Motivation and Related Work:

    • Building on previous studies (e.g., He et al., 2014), this paper aims to comprehensively evaluate research methods and existing issues regarding self-efficacy in the cybersecurity domain.

Solution

  • Proposed Methods or Solutions:

    • This paper systematically reviewed 174 studies conducted between 2010 and 2021, analyzing:
      1. The quality and methods of measuring cybersecurity self-efficacy.
      2. The role of self-efficacy in theoretical frameworks.
      3. Intervention designs targeting self-efficacy.
    • Multi-database searches, dual coding, and strict exclusion criteria were employed to minimize selection bias.
  • Innovative Contributions:

    • Conducted a systematic evaluation of the fragmentation issue across interdisciplinary literature and proposed recommendations for data standardization.
    • Provided an extensive variable analysis, categorizing variables as "causes," "outcomes," or "both."
  • Implementation Steps and Techniques:

    • Data collection utilized 18 databases, covering both quantitative and qualitative studies.
    • Variables coded included sample information, study types, measurement tools, psychometric properties, and intervention methods.
    • Both quantitative and qualitative analysis methods were applied, including data aggregation, network analysis, and exploratory statistics.

Research Findings

  • Specific Findings:

    • Identified 173 unique tools for measuring cybersecurity self-efficacy, most of which were used only once.
    • Weak psychometric standards: While average reliability was high, validation analyses (e.g., validity testing) were generally lacking.
    • Extracted and analyzed 55 outcome variables and 51 causal variables, highlighting the diverse yet non-standardized roles of self-efficacy.
    • Only 13 studies designed interventions targeting self-efficacy, none of which were replicated.
  • Comparison with Existing Solutions:

    • Compared to previous reviews (e.g., He et al., 2014), the issues remain unresolved, with measurement tools becoming even more diverse and fragmented.
    • Emphasized the need for improved consistency in psychometric standards and integration of theoretical frameworks.
  • Experimental or Evaluation Results:

    • The weighted average Cronbach α coefficient for newly introduced scales was approximately 0.87, indicating good reliability.
    • Intervention methods primarily focused on training and activity design, suggesting "mastery experiences" as the main mechanism of action.
    • Theoretical frameworks lacked consensus in variable definitions, with multiple pathways or dual causal relationships observed among variables.
  • Limitations and Future Directions:

    • This paper only evaluated data up to 2021, requiring updates over time.
    • Transparency and detailed reporting in studies were insufficient, particularly regarding scale development processes and intervention mechanisms.
    • Future work should focus on scale construction, theoretical simplification, and replication of interventions.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/147732/2024

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3613904.3642432
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2024
emoji_events
Award
No award tagged
group
Authors
6 authors
sell
Subtopics
Privacy Perception & Decision-Making, Cybersecurity Training & Awareness
work
Professions
Cybersecurity Engineers, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
10 related papers