Cybersecurity Knowledge Requirements for Strategic Level Decision Makers

被引:1
|
作者
Garcia-Granados, Fernando [1 ]
Bahsi, Hayretdin [1 ]
机构
[1] Tallinn Univ Technol, Tallinn, Estonia
关键词
strategic level decision makers; cybersecurity knowledge requirements; cybersecurity training; cybersecurity awareness;
D O I
10.34190/ICCWS.20.102
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Assuring an organization's cyber security posture requires the active involvement of decision makers at all levels, particularly strategic level decision makers such as C-level executives. These leaders have the primary responsibility of initiating security programs, publishing organization-wide security policies and are responsible for the oversight of security policy implementation. It is necessary for these executives to be properly informed, trained, and being provided with the tools required to fulfil their strategic management responsibilities. This study aims to provide a list of topics that would serve as knowledge requirements to be used as a basis for training or cyber exercises addressing strategic level decisionmakers who do not have IT or security background, which is the case in most organizations. First, we conducted a literature review to identify an initial topic list. Then, this list was processed in a card sorting survey in which professionals in the roles of CTO, CIO or CISO were requested to determine the required level of knowledge strategic leaders should ideally have on each topic. The results indicate survey participants are more prone to not excluding any topic regardless of its level of technical expertise. They believe strategic leaders should have, at least, a general understanding and awareness of the topics chosen, even if the topics represent a more technical perspective. A general trend was found wherein topics in which business knowledge intersects with security knowledge were consistently ranked with a higher knowledge requirement, mainly relating to business impact.
引用
收藏
页码:559 / 568
页数:10
相关论文
共 50 条
  • [1] Important competences of strategists and decision makers in the Strategic Knowledge Management model
    Miranda, Roberto Campos Da Rocha
    Creating Collaborative Advantage Through Knowledge and Innovation, 2007, 5 : 205 - 220
  • [2] Cybersecurity Knowledge Requirements for a Water Sector Employee
    Thomani, R.
    Marnewick, A.
    Von Solms, S.
    Malatji, M.
    HUMAN ASPECTS OF INFORMATION SECURITY AND ASSURANCE, HAISA 2022, 2022, 658 : 91 - 105
  • [3] PRISM: a strategic decision framework for cybersecurity risk assessment
    Goel, Rajni
    Kumar, Anupam
    Haddow, James
    INFORMATION AND COMPUTER SECURITY, 2020, 28 (04) : 591 - 625
  • [4] Best of Breed ERP: A Dashboard for Strategic Decision Makers
    Rizni, Imaad
    Poravi, Guhanathan
    2018 8TH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS, MODELLING AND SIMULATION (ISMS), 2018, : 58 - 61
  • [5] USE OF NEURAL NETWORKS AS DECISION MAKERS IN STRATEGIC SITUATIONS
    Couraud, Benoit
    Liu, Peilin
    PROCEEDINGS OF 2009 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-6, 2009, : 1280 - 1285
  • [6] Cybersecurity and cyber defence: national level strategic approach
    Galinec, Darko
    Moznik, Darko
    Guberina, Boris
    AUTOMATIKA, 2017, 58 (03) : 273 - 286
  • [7] Supporting Decision Makers with Knowledge Management Systems
    Handzic, Meliha
    PACIFIC ASIA CONFERENCE ON INFORMATION SYSTEMS 2007, SECTIONS 1-6, 2007,
  • [8] Strategic cybersecurity
    Aldaajeh, Saleh
    Alrabaee, Saed
    COMPUTERS & SECURITY, 2024, 141
  • [9] How decision makers evaluate strategic choices and deal with complexity
    Nutt, PC
    DECISION SCIENCES INSTITUTE 1998 PROCEEDINGS, VOLS 1-3, 1998, : 520 - 522
  • [10] Strategic environmental assessment (SEA) and the decision makers or "homo politicus"
    Cassios, C
    STRATEGIC ENVIRONMENTAL ASSESSMENT IN EUROPE, 1998, 14 : 103 - 104