当前位置: X-MOL 学术Journal of Cybersecurity › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
Developing metrics to assess the effectiveness of cybersecurity awareness program
Journal of Cybersecurity Pub Date : 2022-05-23 , DOI: 10.1093/cybsec/tyac006
Sunil Chaudhary 1 , Vasileios Gkioulos 1 , Sokratis Katsikas 1
Affiliation  

Cybersecurity awareness (CSA) is not just about knowing, but also transforming things learned into practice. It is a continuous process that needs to be adjusted in subsequent iterations to improve its usability as well as sustainability. This is possible only if a CSA program is reviewed and evaluated timely. Review and evaluation of an awareness program offer an insight into the program's effectiveness on the audience and organization, an invaluable piece of information for the continuous improvement of the program. Further, it provides the information required by the management and sponsor to decide on whether to invest in the program or not. Despite these advantages, there does not exist a common understanding of what factors to measure and how to measure them during the evaluation process. As a result, we have proposed evaluation metrics for the purpose. In order to do so, we performed a literature review of 32 papers mainly to extract the following data: (i) what factors did the paper measure, and (ii) how did it measure the factors? Next, we adapted the European Literacy Policy Network's four indicators (i.e. impact, sustainability, accessibility, and monitoring) for awareness evaluation to make it appropriate for evaluating a CSA program. We believe that measuring all four indicators will contribute to making the evaluation process systematic, complete, and replicable. More importantly, it will help to produce more inclusive, accurate, and usable results for the future enhancement of the program.

中文翻译:

制定衡量网络安全意识计划有效性的指标

网络安全意识 (CSA) 不仅涉及了解,还涉及将所学知识转化为实践。这是一个持续的过程,需要在后续迭代中进行调整,以提高其可用性和可持续性。这只有在 CSA 计划得到及时审查和评估时才有可能。对宣传计划的审查和评估可以深入了解该计划对受众和组织的有效性,这是持续改进计划的宝贵信息。此外,它还提供了管理层和发起人决定是否投资该计划所需的信息。尽管有这些优势,但对于在评估过程中要衡量哪些因素以及如何衡量这些因素并没有达成共识。因此,为此,我们提出了评估指标。为此,我们对 32 篇论文进行了文献综述,主要是为了提取以下数据:(i)论文测量了哪些因素,以及(ii)如何测量这些因素?接下来,我们调整了欧洲扫盲政策网络的四个指标(即影响、可持续性、可访问性和监控)以进行意识评估,使其适合评估 CSA 计划。我们相信,衡量所有四个指标将有助于使评估过程系统化、完整和可复制。更重要的是,这将有助于产生更具包容性、准确性和实用性的结果,以用于未来的程序改进。(i) 论文衡量了哪些因素,以及 (ii) 它是如何衡量这些因素的?接下来,我们调整了欧洲扫盲政策网络的四个指标(即影响、可持续性、可访问性和监控)以进行意识评估,使其适合评估 CSA 计划。我们相信,衡量所有四个指标将有助于使评估过程系统化、完整和可复制。更重要的是,这将有助于产生更具包容性、准确性和实用性的结果,以用于未来的程序改进。(i) 论文衡量了哪些因素,以及 (ii) 它是如何衡量这些因素的?接下来,我们调整了欧洲扫盲政策网络的四个指标(即影响、可持续性、可访问性和监控)以进行意识评估,使其适合评估 CSA 计划。我们相信,衡量所有四个指标将有助于使评估过程系统化、完整和可复制。更重要的是,这将有助于产生更具包容性、准确性和实用性的结果,以用于未来的程序改进。我们相信,衡量所有四个指标将有助于使评估过程系统化、完整和可复制。更重要的是,这将有助于产生更具包容性、准确性和实用性的结果,以用于未来的程序改进。我们相信,衡量所有四个指标将有助于使评估过程系统化、完整和可复制。更重要的是,这将有助于产生更具包容性、准确性和实用性的结果,以用于未来的程序改进。
更新日期:2022-05-23
down
wechat
bug