11 CSFs for SETA programme effectiveness (presented by life cycle phase)
| Life cycle phase | CSF | Category | Description |
|---|---|---|---|
| Design | CSF-DS1: Conduct an Initial Assessment of Employee Security Awareness | Assessment needs | Determining what the employee understands about the organisation’s security policy and their appreciation of the risks associated with current IS/cyber security threats |
| CSF-DS2: Know Your Audiences to Ensure Content Suitability | Target audiences | Identifying “who your audiences are” to ensure appropriate content is delivered to the various employee types | |
| CSF-DS3: Make a Yearly Plan to Align Goals and Objectives | Goal/Objective | Knowing what is required to be delivered to the employee to ensure that the SETA programme goals meet the specific needs of the organisation | |
| CSF-DS4: Design for Cultural Context and Employee Cultural Diversity | Culture | Understanding the diversity of employee backgrounds (e.g. language, culture, knowledge, level of education, age, gender) so that the IS/cyber security message can be interpreted by all employees | |
| CSF-DS5: Adhere to Organisational Security Policy and the “Law of the Land” | Policy | Focusing on the guidelines and procedures needed to protect the IS assets of the organisation, to ensure that all of the organisational IS/cyber security policies and the “law of the land” are adhered to when designing a SETA programme | |
| CSF-DS6: Build Security Awareness Campaigns | Communication | Updating the employee on how to mitigate against the potential risks associated with an IS/cyber security threat, and keeping them informed on what is coming, and most crucially, why they need to care | |
| Development | CSF-DV1: Sustained Communication of Relevant Messages | Communication | Repeating the IS/cyber security message in various ways to avoid a lapse in employee concentration |
| Implementation | CSF-IM1: Apply Diverse Methods to Deliver Security Awareness Messages | Communication channel | Using various approaches to deliver IS/cyber security awareness messaging (e.g. SMS, emails, online courses, face-to-face meetings, videos, quizzes, posters, screens in public corridors, etc.) so that the employee is reminded frequently of the IS/cyber security issue |
| CSF-IM2: Motivate Employees to Engage in Security Awareness | Motivation | Encouraging the employee to adhere to IS/cyber security policies by earning a bonus, or other recognition (rewards), based on their practices | |
| Evaluation | CSF-EV1: Maintain Quarterly Evaluation of Employee Performance | Periodic assessment | Providing a year-end evaluation summary to measure each employee’s performance (e.g. level of awareness, number of training sessions completed, etc.) and to provide guidance on necessary improvements |
| CSF-EV2: Measure Employee Reporting of Security Incidents | Incident indication | Using phishing campaigns to simulate attacks (knowing how many employees click the suspicious links) to measure the employee awareness and knowledge regarding IS/cyber security issues |
| Life cycle phase | CSF | Category | Description |
|---|---|---|---|
| Design | Assessment needs | Determining what the employee understands about the organisation’s security policy and their appreciation of the risks associated with current IS/cyber security threats | |
| Target audiences | Identifying “who your audiences are” to ensure appropriate content is delivered to the various employee types | ||
| Goal/Objective | Knowing what is required to be delivered to the employee to ensure that the SETA programme goals meet the specific needs of the organisation | ||
| Culture | Understanding the diversity of employee backgrounds (e.g. language, culture, knowledge, level of education, age, gender) so that the IS/cyber security message can be interpreted by all employees | ||
| Policy | Focusing on the guidelines and procedures needed to protect the IS assets of the organisation, to ensure that all of the organisational IS/cyber security policies and the “law of the land” are adhered to when designing a SETA programme | ||
| Communication | Updating the employee on how to mitigate against the potential risks associated with an IS/cyber security threat, and keeping them informed on what is coming, and most crucially, why they need to care | ||
| Development | Communication | Repeating the IS/cyber security message in various ways to avoid a lapse in employee concentration | |
| Implementation | Communication channel | Using various approaches to deliver IS/cyber security awareness messaging (e.g. SMS, emails, online courses, face-to-face meetings, videos, quizzes, posters, screens in public corridors, etc.) so that the employee is reminded frequently of the IS/cyber security issue | |
| Motivation | Encouraging the employee to adhere to IS/cyber security policies by earning a bonus, or other recognition (rewards), based on their practices | ||
| Evaluation | Periodic assessment | Providing a year-end evaluation summary to measure each employee’s performance (e.g. level of awareness, number of training sessions completed, etc.) and to provide guidance on necessary improvements | |
| Incident indication | Using phishing campaigns to simulate attacks (knowing how many employees click the suspicious links) to measure the employee awareness and knowledge regarding IS/cyber security issues |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.