Developing a cyber security culture: Current practices and future needs

被引:50
|
作者
Uchendu, Betsy [1 ]
Nurse, Jason R. C. [1 ]
Bada, Maria [2 ]
Furnell, Steven [3 ]
机构
[1] Univ Kent, Sch Comp, Canterbury, Kent, England
[2] Univ Cambridge, Dept Comp Sci & Technol, Cambridge, England
[3] Univ Nottingham, Sch Comp Sci, Nottingham, England
关键词
Cybersecurity culture; Information security culture; Security awareness; Organisational culture; Management; SMEs; Business; Behaviour; Psychology; INFORMATION-SECURITY; POLICY; MODEL; EMPLOYEES;
D O I
10.1016/j.cose.2021.102387
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
While the creation of a strong security culture has been researched and discussed for decades, it continues to elude many businesses. Part of the challenge faced is distilling per-tinent, recent academic findings and research into useful guidance. In this article, we aim to tackle this issue by conducting a state-of-the-art study into organisational cyber secu-rity culture research. This work investigates four questions, including how cyber security culture is defined, what factors are essential to building and maintaining such a culture, the frameworks proposed to cultivate a security culture and the metrics suggested to as-sess it. Through the application of the PRISMA systematic literature review technique, we identify and analyse 58 research articles from the last 10 years (2010-2020). Our findings demonstrate that while there have been notable changes in the use of terms (e.g., informa-tion security culture and cyber security culture), many of the most influential factors are similar. Top management support, policy and procedures, and awareness for instance, are critical in engendering cyber security culture. Many of the frameworks reviewed revealed common foundations, with organisational culture playing a substantial role in crafting ap-propriate cyber security culture models. Questionnaires and surveys are the most used tool to measure cyber security culture, but there are also concerns as to whether more dynamic measures are needed. For practitioners, this article highlights factors and models essen-tial to the creation and management of a robust security culture. For research, we produce an up-to-date characterisation of the field and also define open issues deserving of further attention such as the role of change management processes and national culture in an en-terprise's cyber security culture. (c) 2021 Elsevier Ltd. All rights reserved.
引用
收藏
页数:23
相关论文
共 50 条
  • [31] Counterpoint developing a clinical pathology curriculum to meet current and future needs
    Wells, Alan
    Smith, Brian
    CLINICAL CHEMISTRY, 2006, 52 (06) : 971 - 972
  • [32] Cryptographic Techniques in Digital Media Security: Current Practices and Future Directions
    Zhang, Gongling
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (08) : 933 - 941
  • [33] Current Trends in Cyber Security for Drones
    Kumar, C. R. S.
    Mohanty, Sanket
    2021 INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2021,
  • [34] Current Cyber Security Challenges in ICS
    Pattanayak, Animesh
    Kirkland, Matt
    2018 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL INTERNET (ICII 2018), 2018, : 202 - 207
  • [35] The Current State of Cyber Security in Ireland
    Lang, Michael
    Dowling, Seamus
    Lennon, Ruth G.
    2022 CYBER RESEARCH CONFERENCE - IRELAND (CYBER-RCI), 2022, : 1 - 2
  • [36] Developing, Testing, and Communicating Earthquake Forecasts: Current Practices and Future Directions
    Mizrahi, Leila
    Dallo, Irina
    van der Elst, Nicholas J.
    Christophersen, Annemarie
    Spassiani, Ilaria
    Werner, Maximilian J.
    Iturrieta, Pablo
    Bayona, Jose A.
    Iervolino, Iunio
    Schneider, Max
    Page, Morgan T.
    Zhuang, Jiancang
    Herrmann, Marcus
    Michael, Andrew J.
    Falcone, Giuseppe
    Marzocchi, Warner
    Rhoades, David
    Gerstenberger, Matt
    Gulia, Laura
    Schorlemmer, Danijel
    Becker, Julia
    Han, Marta
    Kuratle, Lorena
    Marti, Michele
    Wiemer, Stefan
    REVIEWS OF GEOPHYSICS, 2024, 62 (03)
  • [37] Mobile and wireless communications in developing countries: Current practices and future opportunities
    Denko, MK
    ISAS/CITSA 2004: International Conference on Cybernetics and Information Technologies, Systems and Applications and 10th International Conference on Information Systems Analysis and Synthesis, Vol 4, Proceedings, 2004, : 118 - 123
  • [38] Cyber Security Challenges and Wayforward for Developing Countries
    Zareen, Muhammad Sharjeel
    Akhlaq, Monis
    Tariq, Muhammad
    Khalid, Umar
    2013 2ND NATIONAL CONFERENCE ON INFORMATION ASSURANCE (NCIA), 2013, : 7 - 14
  • [39] The Current and Future Role of Microbial Culture Collections in Food Security Worldwide
    Diaz-Rodriguez, Alondra Maria
    Salcedo Gastelum, Lilian Alejandra
    Felix Pablos, Carmen Maria
    Parra-Cota, Fannie Isela
    Santoyo, Gustavo
    Puente, Mariana Laura
    Bhattacharya, Dhruba
    Mukherjee, Joydeep
    de los Santos-villalobos, Sergio
    FRONTIERS IN SUSTAINABLE FOOD SYSTEMS, 2021, 4
  • [40] Cyber security and awareness, investing in a culture of safety
    Manoliu, Alexandru
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON BUSINESS EXCELLENCE, 2022, 16 (01): : 1439 - 1446