From Compliance to Impact: Tracing the Transformation of an Organizational Security Awareness Program

09/14/2023
by   Julie M. Haney, et al.
0

There is a growing recognition of the need for a transformation from organizational security awareness programs focused on compliance – measured by training completion rates – to those resulting in behavior change. However, few prior studies have begun to unpack the organizational practices of the security awareness teams tasked with executing program transformation. We conducted a year-long case study of a security awareness program in a United States (U.S.) government agency, collecting data via field observations, interviews, and documents. Our findings reveal the challenges and practices involved in the progression of a security awareness program from being compliance-focused to emphasizing impact on workforce attitudes and behaviors. We uniquely capture transformational organizational security awareness practices in action via a longitudinal study involving multiple workforce perspectives. Our study insights can serve as a resource for other security awareness programs and workforce development initiatives aimed at better defining the security awareness work role.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/12/2021

Evaluation of Security Training and Awareness Programs: Review of Current Practices and Guideline

Evaluating the effectiveness of security awareness and training programs...
research
01/26/2018

Coordinating Knowledge Work in Multi-Team Programs: Findings from a Large-Scale Agile Development Program

Software development projects have undergone remarkable changes with the...
research
07/13/2020

SMEs Confidentiality Concerns for Security Information Sharing

Small and medium sized enterprises are considered an essential part of t...
research
01/09/2019

Cyber Security Awareness Campaigns: Why do they fail to change behaviour?

The present paper focuses on Cyber Security Awareness Campaigns, and aim...
research
05/27/2021

How to Integrate Security Compliance Requirements with Agile Software Engineering at Scale?

Integrating security into agile software development is an open issue fo...
research
10/11/2021

Classifying SMEs for Approaching Cybersecurity Competence and Awareness

Cybersecurity is increasingly a concern for small and medium-sized enter...
research
05/16/2022

The Role of Resource Awareness in Medical Information System Life Cycle

During the process of medical information system development, resource a...

Please sign up or login with your details

Forgot password? Click here to reset