Paper Type

Complete

Paper Number

1004

Description

Individuals are often considered the weakest link in the cyber security chain, making their cyber security competencies (CSC) crucial as a "human firewall" against cyber-attacks. Current Security Education, Training, and Awareness (SETA) programs often seem to fail due to their "one-size-fits-all" approach. However, to enable more tailored SETA programs, we believe that upstream CSC tests are needed. We utilize the Design Science Research (DSR) framework, as outlined by Peffers et al. (2007), to design a virtual reality (VR) artifact that simulates realistic cyber threat scenarios, such as finding and inserting a malicious USB flash drive. Building on Köpfer et al.'s (2023) model, which specifies seven dimensions of CSC, our work proposes a scalable, customizable, and immersive solution to assess individuals' CSC using VR-based tests. Based on measured competence levels, more tailored SETA programs can be offered to close specific CSC gaps.

Comments

General

Share

COinS
 
Jul 2nd, 12:00 AM

Fortifying the Human Firewall: Designing a Virtual Reality-Based Test to Measure Individuals' Cyber Security Competencies

Individuals are often considered the weakest link in the cyber security chain, making their cyber security competencies (CSC) crucial as a "human firewall" against cyber-attacks. Current Security Education, Training, and Awareness (SETA) programs often seem to fail due to their "one-size-fits-all" approach. However, to enable more tailored SETA programs, we believe that upstream CSC tests are needed. We utilize the Design Science Research (DSR) framework, as outlined by Peffers et al. (2007), to design a virtual reality (VR) artifact that simulates realistic cyber threat scenarios, such as finding and inserting a malicious USB flash drive. Building on Köpfer et al.'s (2023) model, which specifies seven dimensions of CSC, our work proposes a scalable, customizable, and immersive solution to assess individuals' CSC using VR-based tests. Based on measured competence levels, more tailored SETA programs can be offered to close specific CSC gaps.

When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.