Table 4

The relationships between the CSFs across the SETA program lifecycle phases

CSFHas an impact onRelationshipDescription
CSF-DS6: Build Security Awareness CampaignsCSF-EV2: Measure employee reporting of security incidentsValuingEnables the use of a simulation attack to raise employee's knowledge of security incidents and ensures these incidents are reported appropriately
CSF-DS4: Design for Cultural Context and Employee Cultural DiversityCSF-IM1: Apply diverse methods to deliver security awareness messagesContextualizingEnables the use of different communication channels in order to deliver a culturally contextualized security message
CSF-IM1: Apply Diverse Methods to Deliver Security Awareness MessagesCSF-DV1: Sustained communication of relevant messagesRe-emphasizingEnables the use of different communication channels with the aim of repeating important security awareness messages
CSF-IM2: Motivate Employees to Engage in Security AwarenessCSF-DS5: Adhere to organizational security policy and the “Law of the Land”RecognizingEnables the motivation of employees through earning recognitions and rewards for complying with IS security policy and legislation
CSF-EV1: Maintain Quarterly Evaluation of Employee PerformanceCSF-DS3: Make a yearly plan to align goals and objectivesSchedulingEnables the production of a new security plan based on the outcome of the current organizational performance to plan

Source(s): Authors' own creation/work

or Create an Account

Close Modal
Close Modal