A Framework for Evaluating ICT Security Awareness.
Hennie Kruger, Lynette Drevin, Tjaart Steyn · 2006
ICT resources are important assets of any organization and the protection of these resources are equally important. To be able to protect themselves and their profitability, many organizations have established information security awareness programs. In order for a security awareness program to add value to an organization and at the same time make a contribution to the field of information security it is necessary to have a set of methods to study and measure its effect. This paper gives an overview of a suggested framework for evaluating ICT security awareness. Following a brief description of the framework, a more detailed overview on the identification of areas to be evaluated, using a value focused assessment, will be presented. Comments on possible system generated information, that may be used to assist with the evaluation of security behavior of users, will also be presented.