From Compliance to Impact: Tracing the Transformation of an Organizational Security Awareness Program

dc.contributor.advisorLutters, Wayne G.
dc.contributor.authorHaney, Julie M.
dc.contributor.authorLutters, Wayne G.
dc.date.accessioned2023-09-15T17:35:26Z
dc.date.available2023-09-15T17:35:26Z
dc.date.issued2023-09-15
dc.description.abstractThere is a growing recognition of the need for a transformation from organizational security awareness programs focused on compliance − measured by training completion rates − to those resulting in behavior change. However, few prior studies have begun to unpack the organizational practices of the security awareness teams tasked with executing program transformation. We conducted a year-long case study of a security awareness program in a United States (U.S.) government agency, collecting data via field observations, interviews, and documents. Our findings reveal the challenges and practices involved in the progression of a security awareness program from being compliance-focused to emphasizing impact on workforce attitudes and behaviors. We uniquely capture transformational organizational security awareness practices in action via a longitudinal study involving multiple workforce perspectives. Our study insights can serve as a resource for other security awareness programs and workforce development initiatives aimed at better defining the security awareness work role.
dc.description.urihttps://doi.org/10.48550/arXiv.2309.07724
dc.identifierhttps://doi.org/10.13016/dspace/mnc3-lczw
dc.identifier.citationHaney, Julie M. and Wayne Lutters (2023) From Compliance to Impact: Tracing the Transformation of an Organizational Security Awareness Program, https://doi.org/10.48550/arXiv.2309.07724 [cs.CR, cs.HC]
dc.identifier.urihttp://hdl.handle.net/1903/30508
dc.publisherarXiv.org
dc.relation.isAvailableAtCollege of Information Studiesen_us
dc.relation.isAvailableAtInformation Studiesen_us
dc.relation.isAvailableAtDigital Repository at the University of Marylanden_us
dc.relation.isAvailableAtUniversity of Maryland (College Park, MD)en_us
dc.rightsAttribution-NonCommercial-NoDerivs 3.0 United States*
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/3.0/us/*
dc.subjectcybersecurity, security awareness, training, compliance, measures, case study
dc.titleFrom Compliance to Impact: Tracing the Transformation of an Organizational Security Awareness Program
dc.typeArticle
local.equitableAccessSubmissionYes

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
FromComplianceToImpact.pdf
Size:
414.7 KB
Format:
Adobe Portable Document Format