Event Title
A Practical Guideline for Developing a Managerial Information Security Awareness Program
Loading...
Paper Type
Complete
Abstract
Human action is a major cause for cyber security incidents in organizations. One user group particularly exposed to risk is senior management. Even though managerial information security awareness (MISA) is of high relevance, there is a lack of support on the development of MISA programs from academia. Applying Hevner’s design science research approach, the goal of this study is to create an artifact—a MISA guide, which is fed from literature reviews and qualitative interviews with senior managers and cyber security awareness experts. According to experts interviewed in the evaluation phase, the created artifact was verified to be usable as well as applicable and the results were deemed correct and complete. The evaluation findings indicate that more investigations should be conducted such as to analyze the relationship between ‘organizational security culture’ and the ‘security awareness of senior managers’.
Recommended Citation
Schneider, Bettina; Asprion, Petra Maria; Androvicsova, Simona; and Azan, Wilfrid, "A Practical Guideline for Developing a Managerial Information Security Awareness Program" (2020). AMCIS 2020 Proceedings. 18.
https://aisel.aisnet.org/amcis2020/info_security_privacy/info_security_privacy/18
A Practical Guideline for Developing a Managerial Information Security Awareness Program
Human action is a major cause for cyber security incidents in organizations. One user group particularly exposed to risk is senior management. Even though managerial information security awareness (MISA) is of high relevance, there is a lack of support on the development of MISA programs from academia. Applying Hevner’s design science research approach, the goal of this study is to create an artifact—a MISA guide, which is fed from literature reviews and qualitative interviews with senior managers and cyber security awareness experts. According to experts interviewed in the evaluation phase, the created artifact was verified to be usable as well as applicable and the results were deemed correct and complete. The evaluation findings indicate that more investigations should be conducted such as to analyze the relationship between ‘organizational security culture’ and the ‘security awareness of senior managers’.
When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.