From Compliance to Impact: Tracing the Transformation of an Organizational Security Awareness Program
dc.contributor.advisor | Lutters, Wayne G. | |
dc.contributor.author | Haney, Julie M. | |
dc.contributor.author | Lutters, Wayne G. | |
dc.date.accessioned | 2023-09-15T17:35:26Z | |
dc.date.available | 2023-09-15T17:35:26Z | |
dc.date.issued | 2023-09-15 | |
dc.description.abstract | There is a growing recognition of the need for a transformation from organizational security awareness programs focused on compliance − measured by training completion rates − to those resulting in behavior change. However, few prior studies have begun to unpack the organizational practices of the security awareness teams tasked with executing program transformation. We conducted a year-long case study of a security awareness program in a United States (U.S.) government agency, collecting data via field observations, interviews, and documents. Our findings reveal the challenges and practices involved in the progression of a security awareness program from being compliance-focused to emphasizing impact on workforce attitudes and behaviors. We uniquely capture transformational organizational security awareness practices in action via a longitudinal study involving multiple workforce perspectives. Our study insights can serve as a resource for other security awareness programs and workforce development initiatives aimed at better defining the security awareness work role. | |
dc.description.uri | https://doi.org/10.48550/arXiv.2309.07724 | |
dc.identifier | https://doi.org/10.13016/dspace/mnc3-lczw | |
dc.identifier.citation | Haney, Julie M. and Wayne Lutters (2023) From Compliance to Impact: Tracing the Transformation of an Organizational Security Awareness Program, https://doi.org/10.48550/arXiv.2309.07724 [cs.CR, cs.HC] | |
dc.identifier.uri | http://hdl.handle.net/1903/30508 | |
dc.publisher | arXiv.org | |
dc.relation.isAvailableAt | College of Information Studies | en_us |
dc.relation.isAvailableAt | Information Studies | en_us |
dc.relation.isAvailableAt | Digital Repository at the University of Maryland | en_us |
dc.relation.isAvailableAt | University of Maryland (College Park, MD) | en_us |
dc.rights | Attribution-NonCommercial-NoDerivs 3.0 United States | * |
dc.rights.uri | http://creativecommons.org/licenses/by-nc-nd/3.0/us/ | * |
dc.subject | cybersecurity, security awareness, training, compliance, measures, case study | |
dc.title | From Compliance to Impact: Tracing the Transformation of an Organizational Security Awareness Program | |
dc.type | Article | |
local.equitableAccessSubmission | Yes |
Files
Original bundle
1 - 1 of 1
Loading...
- Name:
- FromComplianceToImpact.pdf
- Size:
- 414.7 KB
- Format:
- Adobe Portable Document Format