Cybersecurity Awareness and Training (CAT) Framework for Remote Working Employees

被引:13
作者
Hijji, Mohammad [1 ]
Alam, Gulzar [2 ]
机构
[1] Univ Tabuk, Fac Comp & Informat Technol, Tabuk 71491, Saudi Arabia
[2] Ulster Univ, Sch Comp, Belfast BT15 1ED, Antrim, North Ireland
关键词
artificial intelligence; cybersecurity; COVID-19; education; cybersecurity awareness; training framework; SECURITY; GAME; PROGRAM; MODEL;
D O I
10.3390/s22228663
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Currently, cybersecurity plays an essential role in computing and information technology due to its direct effect on organizations' critical assets and information. Cybersecurity is applied using integrity, availability, and confidentiality to protect organizational assets and information from various malicious attacks and vulnerabilities. The COVID-19 pandemic has generated different cybersecurity issues and challenges for businesses as employees have become accustomed to working from home. Firms are speeding up their digital transformation, making cybersecurity the current main concern. For software and hardware systems protection, organizations tend to spend an excessive amount of money procuring intrusion detection systems, antivirus software, antispyware software, and encryption mechanisms. However, these solutions are not enough, and organizations continue to suffer security risks due to the escalating list of security vulnerabilities during the COVID-19 pandemic. There is a thriving need to provide a cybersecurity awareness and training framework for remote working employees. The main objective of this research is to propose a CAT framework for cybersecurity awareness and training that will help organizations to evaluate and measure their employees' capability in the cybersecurity domain. The proposed CAT framework will assist different organizations in effectively and efficiently managing security-related issues and challenges to protect their assets and critical information. The developed CAT framework consists of three key levels and twenty-five core practices. Case studies are conducted to evaluate the usefulness of the CAT framework in cybersecurity-based organizational settings in a real-world environment. The case studies' results showed that the proposed CAT framework can identify employees' capability levels and help train them to effectively overcome the cybersecurity issues and challenges faced by the organizations.
引用
收藏
页数:23
相关论文
共 82 条
[1]   Blockchain-Based Authentication in Internet of Vehicles: A Survey [J].
Abbas, Sohail ;
Abu Talib, Manar ;
Ahmed, Afaf ;
Khan, Faheem ;
Ahmad, Shabir ;
Kim, Do-Hyeun .
SENSORS, 2021, 21 (23)
[2]   An overview of social engineering malware: Trends, tactics, and implications [J].
Abraham, Sherly ;
Chengalur-Smith, InduShobha .
TECHNOLOGY IN SOCIETY, 2010, 32 (03) :183-196
[3]   Performance Evaluation of Topological Infrastructure in Internet-of-Things-Enabled Serious Games [J].
Ahmad, Shabir ;
Khan, Faheem ;
Whangbo, Taeg Keun .
CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 71 (02) :2653-2666
[4]  
Ahmed S.R., 2007, Secure software development: Identification of security activities and their integration in software development lifecycle
[5]   DF-C2M2: A Capability Maturity Model for Digital Forensics Organisations [J].
Al-Hanaei, Ebrahim Hamad ;
Rashid, Awais .
2014 IEEE SECURITY AND PRIVACY WORKSHOPS (SPW 2014), 2014, :57-60
[6]  
Alghamdi M. I., 2021, Materials Today: Proceedings, DOI [https://doi.org/10.1016/j.matpr.2021.04.093, DOI 10.1016/J.MATPR.2021.04.093]
[7]   A Holistic Cybersecurity Maturity Assessment Framework for Higher Education Institutions in the United Kingdom [J].
Aliyu, Aliyu ;
Maglaras, Leandros ;
He, Ying ;
Yevseyeva, Iryna ;
Boiten, Eerke ;
Cook, Allan ;
Janicke, Helge .
APPLIED SCIENCES-BASEL, 2020, 10 (10)
[8]  
Almuhammadi S., 2017, Information Security Maturity Model for Nist Cyber Security Framework, V7, P51, DOI DOI 10.5121/CSIT.2017.70305
[9]  
Alwan H.B., 2019, International Journal of Legal Information, V47, P70
[10]  
[Anonymous], IEEE Journals & Magazine