错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Toward a Framework to Improve Employees’ Compliance with Cybersecurity Policy in Organizations

  • Reneuoe Thamae,
  • Hanifa Abdullah,
  • Mathias Mujinga

摘要

Digital transformation has influenced organizations’ operations significantly. However, non-compliance with cybersecurity policy (CSP) is a growing concern for organizations. Technology alone cannot protect organizational cyber assets such as computer systems, networks, and data. Human aspects should be considered when designing and implementing a CSP. The lack of effective CSP training and awareness programs (CSPTAP) is attributable to employees’ non-compliance with the CSP. This paper aims to develop a framework to enhance employees’ compliance with the CSP by implementing effective CSPTAP. Drawing from the present literature and reflecting on the existing behavior change wheel (BCW) framework, and capability, opportunity, motivation, and behavior (COM-B) model, the cybersecurity policy compliance (CSPC) framework is developed. The CSPC framework comprises the following key concepts: learning existing policies, conducting employees’ gap analysis, reviewing existing policies/developing new policies, provision of relevant content and delivery mode, and periodic auditing. These key concepts are essential elements in cybersecurity policy compliance. The model indicates that the implementation of the essential elements will substantially influence employees’ compliance with CSP. Moreover, when organizations consider these key elements, cybersecurity policy training and awareness, can positively enhance employees’ CSP compliance. The proposed development of CSPTAP provides a firm base for future empirical work including action research.