The relationships between the CSFs within the SETA program lifecycle phases
| CSF | Has an impact on | Relationship | Description |
|---|---|---|---|
| CSF-DS3: Make a Yearly Plan to Align Goals and Objectives | CSF-DS4: Design for cultural context and employee cultural diversity | Planning | Enables the design of a programme plan that aligns with the organizational cultural context |
| CSF-DS5: Adhere to organizational security policy and the “Law of the Land” | Enables the design of a programme plan that considers organizational security policy and geographical legislation | ||
| CSF-DS1: Conduct an Initial Assessment of Employee Security Awareness | CSF-DS6: Build security awareness campaigns | Informing | Enables the delivery of appropriate campaign materials reflecting the awareness and knowledge levels of the target audiences |
| CSF-DS2: Know Your Audiences to Ensure Content Suitability | |||
| CSF-IM1: Apply Diverse Methods to Deliver Security Awareness Messages | CSF-IM2: Motivate employees to engage in security awareness | Encouraging | Enables the use of different communication methods to motivate employees to engage with IS security training materials |
| CSF-EV2: Measure Employee Reporting of Security Incidents | CSF-EV1: Maintain quarterly evaluation of employee performance | Assessing | Enables the performance of an employee to be evaluated using the number of security incidents reported by the employee |
| CSF | Has an impact on | Relationship | Description |
|---|---|---|---|
| Enables the design of a programme plan that aligns with the organizational cultural context | |||
| Enables the design of a programme plan that considers organizational security policy and geographical legislation | |||
| Enables the delivery of appropriate campaign materials reflecting the awareness and knowledge levels of the target audiences | |||
| Enables the use of different communication methods to motivate employees to engage with IS security training materials | |||
| Enables the performance of an employee to be evaluated using the number of security incidents reported by the employee |
Source(s): Authors' own creation/work
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.