A systematic literature review of how cybersecurity-related behavior has been assessed

被引:13
|
作者
Kannelonning, Kristian [1 ]
Katsikas, Sokratis K. [1 ]
机构
[1] Norwegian Univ Sci & Technol, Dept Informat Secur & Commun Technol, Gjovik, Norway
关键词
Cybersecurity; Human behavior; Assessment process; INFORMATION SECURITY POLICY; IMPACT; DETERRENCE; AWARENESS;
D O I
10.1108/ICS-08-2022-0139
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose- Cybersecurity attacks on critical infrastructures, businesses and nations are rising and have reached the interest of mainstream media and the public's consciousness. Despite this increased awareness, humans are still considered the weakest link in the defense against an unknown attacker. Whatever the reason, naive-, unintentional- or intentional behavior of a member of an organization, the result of an incident can have a considerable impact. A security policy with guidelines for best practices and rules should guide the behavior of the organization's members. However, this is often not the case. This paper aims to provide answers to how cybersecurity-related behavior is assessed.Design/methodology/approach-Research questions were formulated, and a systematic literature review (SLR) was performed by following the recommendations of the Preferred Reporting Items for Systematic Reviews and Meta-Analyses statement. The SLR initially identified 2,153 articles, and the paper reviews and reports on 26 articles.Findings- The assessment of cybersecurity-related behavior can be classified into three components, namely, data collection, measurement scale and analysis. The findings show that subjective measurements from self-assessment questionnaires are the most frequently used method. Measurement scales are often composed based on existing literature and adapted by the researchers. Partial least square analysis is the most frequently used analysis technique. Even though useful insight and noteworthy findings regarding possible differences between manager and employee behavior have appeared in some publications, conclusive answers to whether such differences exist cannot be drawn.Research limitations/implications- Research gaps have been identified, that indicate areas of interest for future work. These include the development and employment of methods for reducing subjectivity in the assessment of cybersecurity-related behavior.Originality/value- To the best of the authors' knowledge, this is the first SLR on how cybersecurity-related behavior can be assessed. The SLR analyzes relevant publications and identifies current practices as well as their shortcomings, and outlines gaps that future research may bridge.
引用
收藏
页码:463 / 477
页数:15
相关论文
共 50 条
  • [31] A Systematic Literature Review on Cyber Threat Intelligence for Organizational Cybersecurity Resilience
    Saeed, Saqib
    Suayyid, Sarah A.
    Al-Ghamdi, Manal S.
    Al-Muhaisen, Hayfa
    Almuhaideb, Abdullah M.
    SENSORS, 2023, 23 (16)
  • [32] Process mining usage in cybersecurity and software reliability analysis: A systematic literature review
    Macak, Martin
    Daubner, Lukas
    Sani, Mohammadreza Fani
    Buhnova, Barbora
    ARRAY, 2022, 13
  • [33] The use of multi-task learning in cybersecurity applications: a systematic literature review
    Ibrahim, Shimaa
    Catal, Cagatay
    Kacem, Thabet
    Neural Computing and Applications, 2024, 36 (35) : 22053 - 22079
  • [34] Cybersecurity of Autonomous Vehicles: A Systematic Literature Review of Adversarial Attacks and Defense Models
    Girdhar, Mansi
    Hong, Junho
    Moore, John
    IEEE OPEN JOURNAL OF VEHICULAR TECHNOLOGY, 2023, 4 : 417 - 437
  • [35] Cybersecurity Risk Assessment for Medium-Risk Drones: A Systematic Literature Review
    Alexandre, Rui Carlos Josino
    Martins, Luiz Eduardo Galvao
    Gorschek, Tony
    IEEE AEROSPACE AND ELECTRONIC SYSTEMS MAGAZINE, 2023, 38 (06) : 28 - 43
  • [36] The role of cybersecurity as a preventive measure in digital tourism and travel: a systematic literature review
    Florido-Benitez, Lazaro
    DISCOVER COMPUTING, 2025, 28 (01)
  • [37] Enterprise architecture modeling for cybersecurity analysis in critical infrastructures -A systematic literature review
    Jiang, Yuning
    Jeusfeld, Manfred A.
    Mosaad, Michael
    Oo, Nay
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2024, 46
  • [38] How Is Quality of Life Assessed in People With Dementia? A Systematic Literature Review and a Primer for Speech-Language Pathologists
    Heuer, Sabine
    Willer, Rebecca
    AMERICAN JOURNAL OF SPEECH-LANGUAGE PATHOLOGY, 2020, 29 (03) : 1702 - 1715
  • [39] Cybersecurity research from a management perspective: A systematic literature review and future research agenda
    Lohrke, Franz T.
    Frownfelter-Lohrke, Cynthia
    JOURNAL OF GENERAL MANAGEMENT, 2023,
  • [40] Cause-related marketing: a systematic review of the literature
    Bhatti, Hina Yaqub
    Galan-Ladero, M. Mercedes
    Galera-Casquet, Clementina
    INTERNATIONAL REVIEW ON PUBLIC AND NONPROFIT MARKETING, 2023, 20 (01) : 25 - 64