Title
How Effective Is Your Security Awareness Program? An Evaluation Methodology
Abstract
Security awareness is an important element of every security infrastructure, especially since the human factor often proves to be the weakest link. Companies and organizations have developed programs that seek to promote security and enhance users' perception of the importance of exercising security. As raising awareness, however, is an on-going effort, the campaign has to be regularly evaluated so that corrective actions can be taken in order to achieve the best results. This paper addresses the importance of evaluating an organization's awareness program and provides guidelines and a methodology that will help organizations assess their efforts. The proposed framework includes the evaluation of individual awareness-related processes via respective metrics as well as the aggregation of the aforementioned metrics to produce an overall evaluation score, usable both as a benchmark for future iterations of the evaluation program as well as a figure presentable to higher management.
Year
DOI
Venue
2012
10.1080/19393555.2012.747234
Information Security Journal: A Global Perspective
Keywords
Field
DocType
security awareness program,figure presentable,security awareness,corrective action,best result,aforementioned metrics,evaluation program,awareness program,evaluation methodology,overall evaluation score,respective metrics,security infrastructure,security management
USable,Security awareness,Security testing,Computer security,Computer science,Security information and event management,Countermeasure (computer),Perception,Security management
Journal
Volume
Issue
ISSN
21
6
1939-3555
Citations 
PageRank 
References 
7
0.50
10
Authors
3
Name
Order
Citations
PageRank
Konstantinos Rantos13911.16
Konstantinos Fysarakis28315.84
Charalampos Manifavas332243.40