The relationships between the CSFs across the SETA program lifecycle phases
| CSF | Has an impact on | Relationship | Description |
|---|---|---|---|
| CSF-DS6: Build Security Awareness Campaigns | CSF-EV2: Measure employee reporting of security incidents | Valuing | Enables the use of a simulation attack to raise employee's knowledge of security incidents and ensures these incidents are reported appropriately |
| CSF-DS4: Design for Cultural Context and Employee Cultural Diversity | CSF-IM1: Apply diverse methods to deliver security awareness messages | Contextualizing | Enables the use of different communication channels in order to deliver a culturally contextualized security message |
| CSF-IM1: Apply Diverse Methods to Deliver Security Awareness Messages | CSF-DV1: Sustained communication of relevant messages | Re-emphasizing | Enables the use of different communication channels with the aim of repeating important security awareness messages |
| CSF-IM2: Motivate Employees to Engage in Security Awareness | CSF-DS5: Adhere to organizational security policy and the “Law of the Land” | Recognizing | Enables the motivation of employees through earning recognitions and rewards for complying with IS security policy and legislation |
| CSF-EV1: Maintain Quarterly Evaluation of Employee Performance | CSF-DS3: Make a yearly plan to align goals and objectives | Scheduling | Enables the production of a new security plan based on the outcome of the current organizational performance to plan |
| CSF | Has an impact on | Relationship | Description |
|---|---|---|---|
| Enables the use of a simulation attack to raise employee's knowledge of security incidents and ensures these incidents are reported appropriately | |||
| Enables the use of different communication channels in order to deliver a culturally contextualized security message | |||
| Enables the use of different communication channels with the aim of repeating important security awareness messages | |||
| Enables the motivation of employees through earning recognitions and rewards for complying with IS security policy and legislation | |||
| Enables the production of a new security plan based on the outcome of the current organizational performance to plan |
Source(s): Authors' own creation/work
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.