Abstract
Advanced Persistent Threats (APTs) have been growing with social engineering and corporate e-mail compromise reported as the two most penetration vectors to organizational networks. Historically, users (i.e., office assistants, managers, executives) have access to sensitive data and represent up to 95% of cybersecurity threats to organizations. This study addressed the problem of threats to organizational information systems (IS) due to vulnerabilities and breaches caused by employees. While in the past, only selected employees at the organization had access to the computer networks, with the proliferation of mobile devices almost all employees and vendors/contractors have access to the organizational networks. Computer and mobile device users are one of the weakest links in the cybersecurity chain, due to their limited cybersecurity skills (CySs). Over the years, the measures of CySs of computer users were based on self reported surveys or measured knowledge only. Prior IS and medical research found participants view scenarios as nonintrusive and unintimidating, while providing a realistic way to assess various situations from sexual harassment to chemical hazards. Therefore, this paper discusses the validation stage of a cybersecurity threats situational assessment tool that utilizes vignettes with observable hands-on tasks to measure and quantify CySs. Discussions and future research are also presented.
Cite
CITATION STYLE
Carlton, M., Levy, Y., & Ramim, M. (2018). Validation of a vignettes-based, hands-on cybersecurity threats situational assessment tool. Online Journal of Applied Knowledge Management, 6(1), 107–118. https://doi.org/10.36965/ojakm.2018.6(1)107-118
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.