Table C1

The supporting literature for the CSFs

CSFLifecycle phaseCategorySupporting literature
CSF#1 (Conduct an Initial Assessment of Employee Security Awareness)DesignAssessment NeedsAlshaikh et al. (2021), Alshaikh et al. (2018), Puhakainen and Siponen (2010), Okenyi and Owens (2007), Peltier (2005) and Vroom and von Solms (2002) 
CSF#2 (Build Security Awareness Campaigns)CommunicationAlshaikh et al. (2021), Alshaikh et al. (2018), Hearth et al. (2018), Rantos et al. (2012), Puhakainen and Siponen (2010), D'arcy et al. 2009 and Vroom and von Solms (2002) 
CSF#3 (Design for Cultural Context and Employee Cultural Diversity)CultureKirova and Baumöl (2018), Karjalainen et al. (2013), Hovav and D’Arcy (2012), von Solms and von Solms (2004) and Walsham (2002) 
CSF#4 (Make a Yearly Plan to Align Goals and Objectives)Goal/ObjectiveAlshaikh et al. (2021), Alshaikh et al. (2018), Rantos and Manifavas (2012), Peltier (2005) and Hansche (2001) 
CSF#5 (Adhere to Organizational Security Policy and the “Law of the Land”)PolicyKirova and Baumöl (2018), D'arcy et al. (2009) and Peltier (2005) 
CSF#6 (Know Your Audiences to Ensure Content Suitability)Target AudiencesAlshaikh et al. (2021), Kirova and Baumöl et al. (2018), De Maeyer (2007), Peltier (2005) and Siponen (2000) 
CSF#7 (Sustained Communication of Relevant Messages)DevelopmentCommunicationBarlow et al. (2018), Kirova and Baumöl (2018) 
CSF#8 (Apply Diverse Methods to Deliver Security Awareness Messages)ImplementationCommunication ChannelAlshaikh et al. (2021), Silic and Lowry (2020), Alshaikh et al. (2018), Bauer et al. (2017), Tsohou et al. (2015), Johnson (2006) and Peltier (2005) 
CSF#9 (Motivate Employees to Engage in Security Awareness)MotivationSilic and Lowry (2020), Alshaikh et al. (2018), Kirova and Baumöl (2018), Zani et al. (2018), Karjalainen et al. (2013), Puhakainen and Siponen (2010) and Herath and Rao (2009) 
CSF#10 (Maintain Quarterly Evaluation of Employee Performance)EvaluationPeriodic AssessmentAlshaikh et al. (2018), Kirova and Baumöl (2018), Rantos et al. (2012) and Johnson (2006) 
CSF#11 (Measure Employee Reporting of Security Incidents)Incident IndicationAlshaikh et al. (2018), Chen et al. (2015), D'arcy et al., (2009) and Peltier (2005) 

Source(s): Author's own creation/work

or Create an Account

Close Modal
Close Modal