“Cybersecurity Computer-Based Training and Technical Communication Design”
by Lysandwr McNary | Xchanges 9.2
Literature Review
e-Learning Tools and Principles of Design
Technical communicators who create digital technical communication instruments such as web sites and e-Learning modules are increasingly challenged by evolving technology. They must not only keep up to date with the changing arsenal of techniques and technologies, but also discern the most effective modalities. Clark and Meyer warned in their foundational instructional science (2008) text of the dangers in over or under use of technology in ways that defeat knowledge transfer and procedural compliance. The rise of disciplines and design principles such as information architecture, games research, and virtual world creation have radically affected the technical communication environment.
Crystal (2007) addressed fundamental principles in information architecture as applied to user information needs, emphasizing how information architecture has tended to apply classic principles of information organization to the human-computer interface. He promoted a faceted architecture, with the inherently subjective nature of information classified by users as well as designers. Ford and Mott (2007) addressed the role of technical communicators in the creation of information objects, supporting the requirement of effectiveness and user-relevance by emphasizing ISO 13407 (Human-centered design processes for interactive systems) standards in design and usability modeling.
Moving from the general aspect to the specific of e-Learning creation, the issues of user-relevance and user-interface are of even higher priority. Padmanabhan (2009) described design approaches for technical communicators that focus on goal-based scenarios and support active learning by the participant. He differentiated between less complex instructional tasks that can be effectively communicated with traditional, linear materials, and critical learning situations where long-term recall is required and that have external repercussions. A consequence-free learning environment allows learners to make errors in order to develop a deep knowledge base.
In developing digital learning environments, Bronack et al. (2008) outlined specific requirements technical communicators must consider to design effective virtual worlds, including comprehensive thematic design of space, promoting a sense of presence, and consideration of human behaviors in online social environments. Araki and Carliner (2008) reviewed literature addressing the differences between gaming and social virtual worlds, highlighting the virtual world value of combining simulated learning with developing skills, and noting the complexity of creating professional avatars.
Cybersecurity and CBT
A review of the literature regarding CBT training element evaluation doesn’t demonstrate that sufficient research has been performed to define best practices and techniques specifically for the development of information awareness training modules. Greitzer et al. (2008) defined and addressed the “insider threat” where deliberate or unintentional actions by personnel within the security perimeter create exploitable vulnerabilities leading to cybercrime. They pointed out the clear need for compliance training in information assurance standards, noting that from 2004 to 2006 companies reporting insider cybercrime events increased by nearly one-third.
Furman et al. (2012) interviewed participants who needed to be alert to online and computer security threats, finding participants lacked the skills required to effectively maintain cybersecurity and reaching the overall conclusion that misperceptions are common and training is insufficient. Greitzer et al. (2007) stated that “what is lacking is an active learning paradigm — grounded in principles of cognition — that helps ensure that students learn the functional value of the material by working directly with the content.”
Assessing usability and effectiveness is a constant challenge. Lentz and de Jong (2008) demonstrated that experts use cognitive shortcuts that actually interfere with predicting novice behavior and identifying user issues. In their study, IT experts greatly overestimated the ability of laypersons to demonstrate technical knowledge — which certainly applies to how usability of cybersecurity training may be inaccurately assessed by IT experts.
Information awareness CBT is a high-demand product; however, due in part to a lack of cross communication between computer science/information technology professionals and technical communicators, acknowledged best practices of instructional digital instrument design and general technical communications are not applied industry-wide. Organizations would benefit from technical communicators well-educated in the specifics of cybersecurity training needs, and technical communicators would benefit from a thorough knowledge of FISMA and NIST mandates and training requirements.
