A systematic literature review of how cybersecurity-related behavior has been assessed

被引:12
|
作者
Kannelonning, Kristian [1 ]
Katsikas, Sokratis K. [1 ]
机构
[1] Norwegian Univ Sci & Technol, Dept Informat Secur & Commun Technol, Gjovik, Norway
关键词
Cybersecurity; Human behavior; Assessment process; INFORMATION SECURITY POLICY; IMPACT; DETERRENCE; AWARENESS;
D O I
10.1108/ICS-08-2022-0139
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose- Cybersecurity attacks on critical infrastructures, businesses and nations are rising and have reached the interest of mainstream media and the public's consciousness. Despite this increased awareness, humans are still considered the weakest link in the defense against an unknown attacker. Whatever the reason, naive-, unintentional- or intentional behavior of a member of an organization, the result of an incident can have a considerable impact. A security policy with guidelines for best practices and rules should guide the behavior of the organization's members. However, this is often not the case. This paper aims to provide answers to how cybersecurity-related behavior is assessed.Design/methodology/approach-Research questions were formulated, and a systematic literature review (SLR) was performed by following the recommendations of the Preferred Reporting Items for Systematic Reviews and Meta-Analyses statement. The SLR initially identified 2,153 articles, and the paper reviews and reports on 26 articles.Findings- The assessment of cybersecurity-related behavior can be classified into three components, namely, data collection, measurement scale and analysis. The findings show that subjective measurements from self-assessment questionnaires are the most frequently used method. Measurement scales are often composed based on existing literature and adapted by the researchers. Partial least square analysis is the most frequently used analysis technique. Even though useful insight and noteworthy findings regarding possible differences between manager and employee behavior have appeared in some publications, conclusive answers to whether such differences exist cannot be drawn.Research limitations/implications- Research gaps have been identified, that indicate areas of interest for future work. These include the development and employment of methods for reducing subjectivity in the assessment of cybersecurity-related behavior.Originality/value- To the best of the authors' knowledge, this is the first SLR on how cybersecurity-related behavior can be assessed. The SLR analyzes relevant publications and identifies current practices as well as their shortcomings, and outlines gaps that future research may bridge.
引用
收藏
页码:463 / 477
页数:15
相关论文
共 50 条
  • [21] A systematic review of mobile payment literature: What has been studied and what should be studied?
    Ha, Jinkyung
    Nam, Changi
    Kim, Seongcheol
    TELECOMMUNICATIONS POLICY, 2024, 48 (07)
  • [22] How Has The Aerobic Exercise Intensity Domain Been Defined For People With Stroke?: A Systematic Review
    Alsulami, T.
    Rogers, A.
    Buckley, J.
    INTERNATIONAL JOURNAL OF STROKE, 2024, 19 (3_SUPPL) : 113 - 114
  • [23] A methodological review of how heterogeneity has been examined in systematic reviews of diagnostic test accuracy
    Dinnes, J
    Deeks, J
    Kirby, J
    Roderick, P
    HEALTH TECHNOLOGY ASSESSMENT, 2005, 9 (12) : 1 - +
  • [24] AI in Cybersecurity Education- A Systematic Literature Review of Studies on Cybersecurity MOOCs
    Laato, Samuli
    Farooq, Ali
    Tenhunen, Henri
    Pitkamaki, Tinja
    Hakkala, Antti
    Airola, Antti
    2020 IEEE 20TH INTERNATIONAL CONFERENCE ON ADVANCED LEARNING TECHNOLOGIES (ICALT 2020), 2020, : 6 - 10
  • [25] Cybersecurity in the Automotive Industry: A Systematic Literature Review (SLR)
    Fernandez de Arroyabe, Ignacio
    Watson, Tim
    Angelopoulou, Olga
    JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2023, 63 (03) : 716 - 734
  • [26] Cybersecurity Testbeds for IoT: A Systematic Literature Review and Taxonomy
    de Santana, Khalil G. Queiroz
    Schwarz, Marcos
    Wangham, Michelle Silva
    JOURNAL OF INTERNET SERVICES AND APPLICATIONS, 2024, 15 (01) : 450 - 473
  • [27] Understanding of Human Factors in Cybersecurity: A Systematic Literature Review
    Rohan, Rohani
    Funilkul, Suree
    Pal, Debajyoti
    Chutimaskul, Wichian
    2021 INTERNATIONAL CONFERENCE ON COMPUTATIONAL PERFORMANCE EVALUATION (COMPE-2021), 2021, : 133 - +
  • [28] Dynamic Risk Assessment in Cybersecurity: A Systematic Literature Review
    Cheimonidis, Pavlos
    Rantos, Konstantinos
    FUTURE INTERNET, 2023, 15 (10)
  • [29] Cybersecurity Testing in Drones Domain: A Systematic Literature Review
    Marchetti, Eda
    Waheed, Tauheed
    Calabro, Antonello
    IEEE ACCESS, 2024, 12 : 171166 - 171184
  • [30] When LLMs meet cybersecurity: a systematic literature review
    Zhang, Jie
    Bu, Haoyu
    Wen, Hui
    Liu, Yongji
    Fei, Haiqiang
    Xi, Rongrong
    Li, Lun
    Yang, Yun
    Zhu, Hongsong
    Meng, Dan
    CYBERSECURITY, 2025, 8 (01):