Table 1.

11 CSFs for SETA programme effectiveness (presented by life cycle phase)

Life cycle phaseCSFCategoryDescription
DesignCSF-DS1: Conduct an Initial Assessment of Employee Security AwarenessAssessment needsDetermining what the employee understands about the organisation’s security policy and their appreciation of the risks associated with current IS/cyber security threats
CSF-DS2: Know Your Audiences to Ensure Content SuitabilityTarget audiencesIdentifying “who your audiences are” to ensure appropriate content is delivered to the various employee types
CSF-DS3: Make a Yearly Plan to Align Goals and ObjectivesGoal/ObjectiveKnowing what is required to be delivered to the employee to ensure that the SETA programme goals meet the specific needs of the organisation
CSF-DS4: Design for Cultural Context and Employee Cultural DiversityCultureUnderstanding the diversity of employee backgrounds (e.g. language, culture, knowledge, level of education, age, gender) so that the IS/cyber security message can be interpreted by all employees
CSF-DS5: Adhere to Organisational Security Policy and the “Law of the Land”PolicyFocusing on the guidelines and procedures needed to protect the IS assets of the organisation, to ensure that all of the organisational IS/cyber security policies and the “law of the land” are adhered to when designing a SETA programme
CSF-DS6: Build Security Awareness CampaignsCommunicationUpdating the employee on how to mitigate against the potential risks associated with an IS/cyber security threat, and keeping them informed on what is coming, and most crucially, why they need to care
DevelopmentCSF-DV1: Sustained Communication of Relevant MessagesCommunicationRepeating the IS/cyber security message in various ways to avoid a lapse in employee concentration
ImplementationCSF-IM1: Apply Diverse Methods to Deliver Security Awareness MessagesCommunication channelUsing various approaches to deliver IS/cyber security awareness messaging (e.g. SMS, emails, online courses, face-to-face meetings, videos, quizzes, posters, screens in public corridors, etc.) so that the employee is reminded frequently of the IS/cyber security issue
CSF-IM2: Motivate Employees to Engage in Security AwarenessMotivationEncouraging the employee to adhere to IS/cyber security policies by earning a bonus, or other recognition (rewards), based on their practices
EvaluationCSF-EV1: Maintain Quarterly Evaluation of Employee PerformancePeriodic assessmentProviding a year-end evaluation summary to measure each employee’s performance (e.g. level of awareness, number of training sessions completed, etc.) and to provide guidance on necessary improvements
CSF-EV2: Measure Employee Reporting of Security IncidentsIncident indicationUsing phishing campaigns to simulate attacks (knowing how many employees click the suspicious links) to measure the employee awareness and knowledge regarding IS/cyber security issues
Source: Authors’ own creation/work

or Create an Account

Close Modal
Close Modal