A Cyber-Security Culture Framework for Assessing Organization Readiness

被引:43
作者
Georgiadou, Anna [1 ]
Mouzakitis, Spiros [1 ]
Bounas, Kanaris [1 ]
Askounis, Dimitrios [1 ]
机构
[1] Natl Tech Univ Athens, Athens, Greece
基金
欧盟地平线“2020”;
关键词
Cybersecurity culture; assessment; awareness; security behavior; INFORMATION; AWARENESS; POLICIES; BEHAVIOR; MANAGEMENT; EMPLOYEES; TAXONOMY;
D O I
10.1080/08874417.2020.1845583
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper presents a cyber-security culture framework for assessing and evaluating the current security readiness of an organization's workforce. Having conducted a thorough review of the most commonly used security frameworks, we identify core security human-related elements and classify them by constructing a domain agnostic security model. We then proceed by presenting in detail each component of our model and attempt to quantify them in order to achieve a feasible assessment methodology. The paper thereafter presents the application of this methodology for the design and development of a security culture evaluation tool, that offers recommendations and alternative approaches to workforce training programs and techniques. The model has been designed to easily adapt on various application domains while focusing on their unique characteristics. The paper concludes on applications of our instrument on security-critical domains, and its contribution to current research by providing deeper insights regarding the human factor in cybersecurity.
引用
收藏
页码:452 / 462
页数:11
相关论文
共 94 条
[1]   User preference of cyber security awareness delivery methods [J].
Abawajy, Jemal .
BEHAVIOUR & INFORMATION TECHNOLOGY, 2014, 33 (03) :236-247
[2]  
All Hazards Consortium (AHC), CYBER SECURITY RISK
[3]  
Alshaikh M, 2014, P 25 AUSTR C INF SYS
[4]   Why we need a new definition of information security [J].
Anderson, JM .
COMPUTERS & SECURITY, 2003, 22 (04) :308-313
[5]  
Andress J., 2016, Building a Practical Information Security Program (Syngress)
[6]  
[Anonymous], CYBERSECURITY CHECKL
[7]  
[Anonymous], 2019, Energy Shield
[8]  
[Anonymous], 2012, COBIT5: A business framework for the governance and management of enterprise IT
[9]  
[Anonymous], 2018, Threat Landscape Report 2017
[10]  
[Anonymous], 2020, Global Cybersecurity Index