Table 5

Evaluating the CSFs against existing SETA program effectiveness literature

PhaseCSFAlshaikh et al. (2018) Alshaikh et al. (2021) Kirova and Baumöl (2018) Silic and Lowry (2020) 
DesignCSF-DS1: Conduct an Initial Assessment of Employee Security AwarenessXX  
CSF-DS2: Know Your Audiences to Ensure Content Suitability XX 
CSF-DS3: Make a Yearly Plan to Align Goals and ObjectivesXX  
CSF-DS4: Design for Cultural Context and Employee Cultural Diversity  X 
CSF-DS5: Adhere to Organizational Security Policy and the “Law of the Land”X   
CSF-DS6: Build Security Awareness CampaignsXX  
DevelopmentCSF-DV1: Sustained Communication of Relevant Messages  X 
ImplementationCSF-IM1: Apply Diverse Methods to Deliver Security Awareness MessagesXX X
CSF-IM2: Motivate Employees to Engage in Security AwarenessX XX
EvaluationCSF-EV1: Maintain Quarterly Evaluation of Employee PerformanceX X 
CSF-EV2: Measure Employee Reporting of Security IncidentsX   
 Total8552

Source(s): Authors' own creation/work

or Create an Account

Close Modal
Close Modal