Selected questions by dimension
| Dimension | Statement |
|---|---|
| Meta | I am interested in cybersecurity |
| Meta | I believe I am an cybersecurity expert |
| Cybersecurity accountability | There is a need for additional training for cybersecurity controls (e.g., multi-factor authentication, cyber security frameworks, incident management) |
| Cybersecurity accountability | Cybersecurity should be part of my company development program |
| Cybersecurity accountability | Action (e.g., disciplinary procedure) should be taken if someone does not adhere to the cybersecurity policy (e.g. if they share passwords, give out confidential information or visit prohibited internet sites |
| Cybersecurity commitment | The company cybersecurity awareness initiatives are effective |
| Cybersecurity commitment | I understand what is expected of me when it comes to cybersecurity/secure behavior at the company |
| Cybersecurity commitment | My unit assigns enough people to cybersecurity |
| Cybersecurity commitment | My unit dedicates enough time to cybersecurity |
| Cybersecurity commitment | My unit encourages compliance to the cybersecurity policy |
| Cybersecurity necessity and Importance | I am aware of the cybersecurity aspects relating to my job function (e.g. how to choose a password or handle confidential information) |
| Cybersecurity necessity and Importance | It is necessary to commit time to cybersecurity |
| Cybersecurity necessity and Importance | Cybersecurity is necessary in my unit |
| Cybersecurity necessity and importance | I am aware of the impact and consequences that a breach of/neglecting security can have for the company |
| Cybersecurity policy effectiveness | The content of the cybersecurity policy was effectively communicated to me |
| Cybersecurity policy effectiveness | I am informed in a timely manner as to how cybersecurity changes will affect me |
| Cybersecurity policy effectiveness | The content of the cybersecurity policy is easy to understand |
| Information usage perception | The company has clear directives on how to protect sensitive/confidential employee information |
| Information usage perception | I believe that it is important to limit the collection and sharing of sensitive, personal information |
| Information usage perception | My colleagues and I take care when talking about confidential information in public places |
| Management buy-in | Managers lead by example when it comes to cybersecurity |
| Management buy-in | My colleagues demonstrate commitment to cybersecurity |
| Management buy-in | Cybersecurity is perceived as important by managers |
| Dimension | Statement |
|---|---|
| Meta | I am interested in cybersecurity |
| Meta | I believe I am an cybersecurity expert |
| Cybersecurity accountability | There is a need for additional training for cybersecurity controls (e.g., multi-factor authentication, cyber security frameworks, incident management) |
| Cybersecurity accountability | Cybersecurity should be part of my company development program |
| Cybersecurity accountability | Action (e.g., disciplinary procedure) should be taken if someone does not adhere to the cybersecurity policy (e.g. if they share passwords, give out confidential information or visit prohibited internet sites |
| Cybersecurity commitment | The company cybersecurity awareness initiatives are effective |
| Cybersecurity commitment | I understand what is expected of me when it comes to cybersecurity/secure behavior at the company |
| Cybersecurity commitment | My unit assigns enough people to cybersecurity |
| Cybersecurity commitment | My unit dedicates enough time to cybersecurity |
| Cybersecurity commitment | My unit encourages compliance to the cybersecurity policy |
| Cybersecurity necessity and Importance | I am aware of the cybersecurity aspects relating to my job function (e.g. how to choose a password or handle confidential information) |
| Cybersecurity necessity and Importance | It is necessary to commit time to cybersecurity |
| Cybersecurity necessity and Importance | Cybersecurity is necessary in my unit |
| Cybersecurity necessity and importance | I am aware of the impact and consequences that a breach of/neglecting security can have for the company |
| Cybersecurity policy effectiveness | The content of the cybersecurity policy was effectively communicated to me |
| Cybersecurity policy effectiveness | I am informed in a timely manner as to how cybersecurity changes will affect me |
| Cybersecurity policy effectiveness | The content of the cybersecurity policy is easy to understand |
| Information usage perception | The company has clear directives on how to protect sensitive/confidential employee information |
| Information usage perception | I believe that it is important to limit the collection and sharing of sensitive, personal information |
| Information usage perception | My colleagues and I take care when talking about confidential information in public places |
| Management buy-in | Managers lead by example when it comes to cybersecurity |
| Management buy-in | My colleagues demonstrate commitment to cybersecurity |
| Management buy-in | Cybersecurity is perceived as important by managers |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.