Author:
Kävrestad Joakim,Burvall Felicia,Nohlberg Marcus
Abstract
Purpose
Developing cybersecurity awareness (CSA) is becoming a more and more important goal for modern organizations. CSA is a complex sociotechnical system where social, technical and organizational aspects affect each other in an intertwined way. With the goal of providing a holistic representation of CSA, this paper aims to develop a taxonomy of factors that contribute to organizational CSA.
Design/methodology/approach
The research used a design science approach including a literature review and practitioner interviews. A taxonomy was drafted based on 71 previous research publications. It was then updated and refined in two iterations of interviews with domain experts.
Findings
The result of this research is a taxonomy which outline six domains for importance for organization CSA. Each domain includes several activities which can be undertaken to increase CSA within an organization. As such, it provides a holistic overview of the CSA field.
Practical implications
Organizations can adopt the taxonomy to create a roadmap for internal CSA practices. For example, an organization could assess how well it performs in the six main themes and use the subthemes as inspiration when deciding on CSA activities.
Originality/value
The output of this research provides an overview of CSA based on information extracted from existing literature and then reviewed by practitioners. It also outlines how different aspects of CSA are interdependent on each other.
Reference88 articles.
1. User preference of cyber security awareness delivery methods;Behaviour and Information Technology,2014
2. Performance analysis of cyber security awareness delivery methods,2010
3. Cyber shield security awareness program,2021
4. The urgent need for an enforced awareness programme to create internet security awareness in Nigeria,2015
5. Information security awareness in university: maintaining learnability, performance and adaptability through roles of responsibility,2011