Human Factors in Information Security: A Capability Framework for Administrative Professionals in the Digital Workplace
The acceleration of digital transformation has reshaped occupational landscapes and amplified the criticality of human-centered safeguards within institutional information ecosystems. Administrative professionals — encompassing executive assistants, office coordinators, secretariat officers, and front-line clerical staff — increasingly occupy strategic gatekeeper positions where sensitive communications, calendars, contracts, and credentials converge. This review interrogates the cognitive, behavioral, organizational and technological dimensions that shape secure practice among such personnel, synthesizing scholarship from human–computer interaction, organizational psychology, information systems research and applied behavioral science. Drawing on a thematic analysis of peer-reviewed and grey literature, the paper situates clerical staff as both a structural attack surface and an indispensable line of defense whose competence demands deliberate cultivation. Findings indicate that prevailing training models, often rooted in compliance-centric pedagogy, neglect contextual realities such as cognitive overload, role ambiguity, fragmented authority over digital tools, and the bounded rationality that conditions everyday workplace decisions. The paper articulates a multi-tier capability architecture organized around foundational awareness, procedural fluency, contextual judgement, and adaptive resilience, integrating policy literacy, social-engineering recognition, credential stewardship, data-handling discipline, and incident-reporting agility. Particular attention is devoted to hybrid and remote configurations that have normalized distributed administrative work, expanding the perimeter of organizational risk. The proposed framework foregrounds an ecological model in which individual competence, supervisory support, organizational culture, and technical scaffolding co-evolve. The review contributes to scholarship by translating fragmented behavioral-security insights into an operationally tractable schema oriented to a frequently overlooked occupational community whose silent diligence underwrites enterprise resilience in an increasingly contested digital environment. Implications for policy, professional development, and future inquiry are articulated to guide both practitioners and scholars.