The supporting literature for the CSFs
| CSF | Lifecycle phase | Category | Supporting literature |
|---|---|---|---|
| CSF#1 (Conduct an Initial Assessment of Employee Security Awareness) | Design | Assessment Needs | Alshaikh et al. (2021), Alshaikh et al. (2018), Puhakainen and Siponen (2010), Okenyi and Owens (2007), Peltier (2005) and Vroom and von Solms (2002) |
| CSF#2 (Build Security Awareness Campaigns) | Communication | Alshaikh et al. (2021), Alshaikh et al. (2018), Hearth et al. (2018), Rantos et al. (2012), Puhakainen and Siponen (2010), D'arcy et al. 2009 and Vroom and von Solms (2002) | |
| CSF#3 (Design for Cultural Context and Employee Cultural Diversity) | Culture | Kirova and Baumöl (2018), Karjalainen et al. (2013), Hovav and D’Arcy (2012), von Solms and von Solms (2004) and Walsham (2002) | |
| CSF#4 (Make a Yearly Plan to Align Goals and Objectives) | Goal/Objective | Alshaikh et al. (2021), Alshaikh et al. (2018), Rantos and Manifavas (2012), Peltier (2005) and Hansche (2001) | |
| CSF#5 (Adhere to Organizational Security Policy and the “Law of the Land”) | Policy | Kirova and Baumöl (2018), D'arcy et al. (2009) and Peltier (2005) | |
| CSF#6 (Know Your Audiences to Ensure Content Suitability) | Target Audiences | Alshaikh et al. (2021), Kirova and Baumöl et al. (2018), De Maeyer (2007), Peltier (2005) and Siponen (2000) | |
| CSF#7 (Sustained Communication of Relevant Messages) | Development | Communication | Barlow et al. (2018), Kirova and Baumöl (2018) |
| CSF#8 (Apply Diverse Methods to Deliver Security Awareness Messages) | Implementation | Communication Channel | Alshaikh et al. (2021), Silic and Lowry (2020), Alshaikh et al. (2018), Bauer et al. (2017), Tsohou et al. (2015), Johnson (2006) and Peltier (2005) |
| CSF#9 (Motivate Employees to Engage in Security Awareness) | Motivation | Silic and Lowry (2020), Alshaikh et al. (2018), Kirova and Baumöl (2018), Zani et al. (2018), Karjalainen et al. (2013), Puhakainen and Siponen (2010) and Herath and Rao (2009) | |
| CSF#10 (Maintain Quarterly Evaluation of Employee Performance) | Evaluation | Periodic Assessment | Alshaikh et al. (2018), Kirova and Baumöl (2018), Rantos et al. (2012) and Johnson (2006) |
| CSF#11 (Measure Employee Reporting of Security Incidents) | Incident Indication | Alshaikh et al. (2018), Chen et al. (2015), D'arcy et al., (2009) and Peltier (2005) |
| CSF | Lifecycle phase | Category | Supporting literature |
|---|---|---|---|
| Design | Assessment Needs | ||
| Communication | |||
| Culture | |||
| Goal/Objective | |||
| Policy | |||
| Target Audiences | |||
| Development | Communication | ||
| Implementation | Communication Channel | ||
| Motivation | |||
| Evaluation | Periodic Assessment | ||
| Incident Indication |
Source(s): Author's own creation/work
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.