Table 2

Key informant frequency and coded excerpt distribution for each CSF

Lifecycle phaseCSF (ranked order within lifecycle phase)CategoryCoded excerptsKI frequencyCSF rank
DesignCSF-DS1: Conduct an Initial Assessment of Employee Security AwarenessAssessment Needs22 (12%)18 (90%)2
CSF-DS2: Know Your Audiences to Ensure Content SuitabilityTarget Audiences21 (11%)18 (90%)3
CSF-DS3: Make a Yearly Plan to Align Goals and ObjectivesGoal/Objective16 (9%)16 (80%)5
CSF-DS4: Design for Cultural Context and Employee Cultural DiversityCulture14 (7%)14 (70%)6
CSF-DS5: Adhere to Organizational Security Policy and the “Law of the Land”Policy11 (6%)11 (55%)9
CSF-DS6: Build Security Awareness CampaignsCommunication11 (6%)9 (45%)11
DevelopmentCSF-DV1: Sustained Communication of Relevant MessagesCommunication14 (7%)12 (60%)8
ImplementationCSF-IM1: Apply Diverse Methods to Deliver Security Awareness MessagesCommunication Channel28 (15%)17 (85%)4
CSF-IM2: Motivate Employees to Engage in Security AwarenessMotivation11 (6%)11 (55%)10
EvaluationCSF-EV1: Maintain Quarterly Evaluation of Employee PerformancePeriodic Assessment24 (13%)20 (100%)1
CSF-EV2: Measure Employee Reporting of Security IncidentsIncident Indication15 (8%)14 (70%)7
Total187 (100%)20 (100%) 

Source(s): Authors' own creation/work

or Create an Account

Close Modal
Close Modal