The proposed model, explained by grades in detail
| Maturity level | Brief description of the level | Controls supporting knowledge | Controls supporting attitude | Audit evidence |
|---|---|---|---|---|
| 1 - Non-Existent | ISA practically does not exist | No supporting controls | No supporting controls | None |
| 2 - Compliance Focused | ISA programme already exists but is designed primarily to meet specific compliance or audit requirements | Regular (annual) and documented awareness training events. General ISA training materials (contents) are available (e.g. videos, newsletters, or presentation materials). Regular (annual) internal audits. As a part of the onboarding process, the employees receive initial training with generic information security content | Documented disciplinary process | Training materials and training records; documented procedures for identifying customer needs, supplier management, and initial and regular ISA training; signed NDAs with employees and suppliers; 3rd party audit reports; certificates of compliance issued by customers and/or third parties; and risk assessment reports |
| 3 - Promoting Awareness & Behavior Change | This ISA grade is based on a detailed risk assessment, which identifies the topics that have the greatest impact on supporting the organization's mission and ISA efforts to focus on those key topics | Based on the risk assessment of the organization, there are available, organization-specific ISA training materials (contents) | During the traditional disciplinary process, there is a defined and documented incentive system, i.e. prizes, trophies, presents, or campaigns related to information security | List of relevant ISA-related topics linked to a detailed risk assessment; management review meeting minutes; ISA project-related documents (PID, project plan, action plan, reports, etc.); regular management communications about emerging risks, actions, countermeasures and results via e-mail, blog, video, etc. |
| 4 - Long-Term Sustainment & Culture Change | There is an ISA-related programme, which has the processes, resources, and leadership support in place for a long-term life cycle, including, at a minimum, an annual review and update of the programme. The programme and security are an established and updated part of the organization's culture | Documented procedures for the regular review of the communicated contents and for defining the learning objectives for target groups. Regular knowledge assessments by tests | IS-related goals are integral parts of the regular personal appraisal system for individuals as a part of performance assessments | Program-related documentation (set of projects, project and programme reports) and a detailed ISA budget for a longer period (i.e. three years) |
| 5 - Robust Metrics Framework | The ISA programme has a robust metrics framework to track progress and measure impact. Consequently, the programme is continuously improving and able to demonstrate a return on investment | Documented and implemented procedures for measuring ISA (metrics, measurement method, and use of the measurement results) | Personalized, tailored to the organizational unit, “SMART” (specific, measurable, attainable, realistic and timely) objectives | Documented, traceable KGIs (Key Governance Indicators), KPIs and ROI (ROSI (Return On Security Investment)) calculations |
| Maturity level | Brief description of the level | Controls supporting knowledge | Controls supporting attitude | Audit evidence |
|---|---|---|---|---|
| 1 - Non-Existent | ISA practically does not exist | No supporting controls | No supporting controls | None |
| 2 - Compliance Focused | ISA programme already exists but is designed primarily to meet specific compliance or audit requirements | Regular (annual) and documented awareness training events. General ISA training materials (contents) are available (e.g. videos, newsletters, or presentation materials). Regular (annual) internal audits. As a part of the onboarding process, the employees receive initial training with generic information security content | Documented disciplinary process | Training materials and training records; documented procedures for identifying customer needs, supplier management, and initial and regular ISA training; signed NDAs with employees and suppliers; 3rd party audit reports; certificates of compliance issued by customers and/or third parties; and risk assessment reports |
| 3 - Promoting Awareness & Behavior Change | This ISA grade is based on a detailed risk assessment, which identifies the topics that have the greatest impact on supporting the organization's mission and ISA efforts to focus on those key topics | Based on the risk assessment of the organization, there are available, organization-specific ISA training materials (contents) | During the traditional disciplinary process, there is a defined and documented incentive system, i.e. prizes, trophies, presents, or campaigns related to information security | List of relevant ISA-related topics linked to a detailed risk assessment; management review meeting minutes; ISA project-related documents (PID, project plan, action plan, reports, etc.); regular management communications about emerging risks, actions, countermeasures and results via e-mail, blog, video, etc. |
| 4 - Long-Term Sustainment & Culture Change | There is an ISA-related programme, which has the processes, resources, and leadership support in place for a long-term life cycle, including, at a minimum, an annual review and update of the programme. The programme and security are an established and updated part of the organization's culture | Documented procedures for the regular review of the communicated contents and for defining the learning objectives for target groups. Regular knowledge assessments by tests | IS-related goals are integral parts of the regular personal appraisal system for individuals as a part of performance assessments | Program-related documentation (set of projects, project and programme reports) and a detailed ISA budget for a longer period (i.e. three years) |
| 5 - Robust Metrics Framework | The ISA programme has a robust metrics framework to track progress and measure impact. Consequently, the programme is continuously improving and able to demonstrate a return on investment | Documented and implemented procedures for measuring ISA (metrics, measurement method, and use of the measurement results) | Personalized, tailored to the organizational unit, “SMART” (specific, measurable, attainable, realistic and timely) objectives | Documented, traceable KGIs (Key Governance Indicators), KPIs and ROI (ROSI (Return On Security Investment)) calculations |
Source(s): Authors' own work
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.