Table 5

The proposed model, explained by grades in detail

Maturity levelBrief description of the levelControls supporting knowledgeControls supporting attitudeAudit evidence
1 - Non-ExistentISA practically does not existNo supporting controlsNo supporting controlsNone
2 - Compliance FocusedISA programme already exists but is designed primarily to meet specific compliance or audit requirementsRegular (annual) and documented awareness training events. General ISA training materials (contents) are available (e.g. videos, newsletters, or presentation materials). Regular (annual) internal audits. As a part of the onboarding process, the employees receive initial training with generic information security contentDocumented disciplinary processTraining materials and training records; documented procedures for identifying customer needs, supplier management, and initial and regular ISA training; signed NDAs with employees and suppliers; 3rd party audit reports; certificates of compliance issued by customers and/or third parties; and risk assessment reports
3 - Promoting Awareness & Behavior ChangeThis ISA grade is based on a detailed risk assessment, which identifies the topics that have the greatest impact on supporting the organization's mission and ISA efforts to focus on those key topicsBased on the risk assessment of the organization, there are available, organization-specific ISA training materials (contents)During the traditional disciplinary process, there is a defined and documented incentive system, i.e. prizes, trophies, presents, or campaigns related to information securityList of relevant ISA-related topics linked to a detailed risk assessment; management review meeting minutes; ISA project-related documents (PID, project plan, action plan, reports, etc.); regular management communications about emerging risks, actions, countermeasures and results via e-mail, blog, video, etc.
4 - Long-Term Sustainment & Culture ChangeThere is an ISA-related programme, which has the processes, resources, and leadership support in place for a long-term life cycle, including, at a minimum, an annual review and update of the programme. The programme and security are an established and updated part of the organization's cultureDocumented procedures for the regular review of the communicated contents and for defining the learning objectives for target groups. Regular knowledge assessments by testsIS-related goals are integral parts of the regular personal appraisal system for individuals as a part of performance assessmentsProgram-related documentation (set of projects, project and programme reports) and a detailed ISA budget for a longer period (i.e. three years)
5 - Robust Metrics FrameworkThe ISA programme has a robust metrics framework to track progress and measure impact. Consequently, the programme is continuously improving and able to demonstrate a return on investmentDocumented and implemented procedures for measuring ISA (metrics, measurement method, and use of the measurement results)Personalized, tailored to the organizational unit, “SMART” (specific, measurable, attainable, realistic and timely) objectivesDocumented, traceable KGIs (Key Governance Indicators), KPIs and ROI (ROSI (Return On Security Investment)) calculations

Source(s): Authors' own work

or Create an Account

Close subscription notice
Close access options