Evaluating the CSFs against existing SETA program effectiveness literature
| Phase | CSF | Alshaikh et al. (2018) | Alshaikh et al. (2021) | Kirova and Baumöl (2018) | Silic and Lowry (2020) |
|---|---|---|---|---|---|
| Design | CSF-DS1: Conduct an Initial Assessment of Employee Security Awareness | X | X | ||
| CSF-DS2: Know Your Audiences to Ensure Content Suitability | X | X | |||
| CSF-DS3: Make a Yearly Plan to Align Goals and Objectives | X | X | |||
| CSF-DS4: Design for Cultural Context and Employee Cultural Diversity | X | ||||
| CSF-DS5: Adhere to Organizational Security Policy and the “Law of the Land” | X | ||||
| CSF-DS6: Build Security Awareness Campaigns | X | X | |||
| Development | CSF-DV1: Sustained Communication of Relevant Messages | X | |||
| Implementation | CSF-IM1: Apply Diverse Methods to Deliver Security Awareness Messages | X | X | X | |
| CSF-IM2: Motivate Employees to Engage in Security Awareness | X | X | X | ||
| Evaluation | CSF-EV1: Maintain Quarterly Evaluation of Employee Performance | X | X | ||
| CSF-EV2: Measure Employee Reporting of Security Incidents | X | ||||
| Total | 8 | 5 | 5 | 2 |
| Phase | CSF | ||||
|---|---|---|---|---|---|
| Design | |||||
| Development | |||||
| Implementation | |||||
| Evaluation | |||||
Source(s): Authors' own creation/work
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.