Cargando…

A systematic literature review of cybersecurity scales assessing information security awareness

Information Security Awareness (ISA) is a significant concept that got considerable attention recently and can assist in minimizing the risks associated with information security breaches. Several measurement scales have been developed in this regard, as measuring users’ ISA is paramount. Although I...

Descripción completa

Detalles Bibliográficos
Autores principales: Rohan, Rohani, Pal, Debajyoti, Hautamäki, Jari, Funilkul, Suree, Chutimaskul, Wichian, Thapliyal, Himanshu
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Elsevier 2023
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10015252/
https://www.ncbi.nlm.nih.gov/pubmed/36938452
http://dx.doi.org/10.1016/j.heliyon.2023.e14234
_version_ 1784907175294926848
author Rohan, Rohani
Pal, Debajyoti
Hautamäki, Jari
Funilkul, Suree
Chutimaskul, Wichian
Thapliyal, Himanshu
author_facet Rohan, Rohani
Pal, Debajyoti
Hautamäki, Jari
Funilkul, Suree
Chutimaskul, Wichian
Thapliyal, Himanshu
author_sort Rohan, Rohani
collection PubMed
description Information Security Awareness (ISA) is a significant concept that got considerable attention recently and can assist in minimizing the risks associated with information security breaches. Several measurement scales have been developed in this regard, as measuring users’ ISA is paramount. Although ISA specific scales are very important, yet what methodological rigor they use in terms of initial conceptualization of ISA, data collection and analysis during the development, and scale validation of such scales are some unknown aspects. Therefore, we provide a comprehensive review of the existing ISA specific scales to address all the above concerns. A popular method, PRISMA, is utilized, and a total of 24 articles that match with criteria of this research are included for the final in-depth analysis. Also, a holistic evaluation framework is developed containing three phases and 19 criteria. Findings revealed that most studies treat ISA as a multi-dimensional construct, and ISA researchers rarely conduct both pilot testing and pre-text evaluation while validating and refining the initial scales. Additionally, several articles did not report some of the essential elements used for checking the rigor of factor analysis, and evidence for validities of the identified scales is inadequate. Consequently, existing ISA specific scales must be improved both in terms of the methodological thoroughness of the scale development procedure and their validities. Moreover, not only justifying why the development of a new scale is necessary, but also improving the quality of the existing scales by doing multiple iterations is significant in the future. Likewise, the inclusion of all the dimensions of ISA, while generating the initial items pool is an important aspect to be considered. A thorough discussion, recommendations for future research, conclusions, and study limitations are provided.
format Online
Article
Text
id pubmed-10015252
institution National Center for Biotechnology Information
language English
publishDate 2023
publisher Elsevier
record_format MEDLINE/PubMed
spelling pubmed-100152522023-03-16 A systematic literature review of cybersecurity scales assessing information security awareness Rohan, Rohani Pal, Debajyoti Hautamäki, Jari Funilkul, Suree Chutimaskul, Wichian Thapliyal, Himanshu Heliyon Research Article Information Security Awareness (ISA) is a significant concept that got considerable attention recently and can assist in minimizing the risks associated with information security breaches. Several measurement scales have been developed in this regard, as measuring users’ ISA is paramount. Although ISA specific scales are very important, yet what methodological rigor they use in terms of initial conceptualization of ISA, data collection and analysis during the development, and scale validation of such scales are some unknown aspects. Therefore, we provide a comprehensive review of the existing ISA specific scales to address all the above concerns. A popular method, PRISMA, is utilized, and a total of 24 articles that match with criteria of this research are included for the final in-depth analysis. Also, a holistic evaluation framework is developed containing three phases and 19 criteria. Findings revealed that most studies treat ISA as a multi-dimensional construct, and ISA researchers rarely conduct both pilot testing and pre-text evaluation while validating and refining the initial scales. Additionally, several articles did not report some of the essential elements used for checking the rigor of factor analysis, and evidence for validities of the identified scales is inadequate. Consequently, existing ISA specific scales must be improved both in terms of the methodological thoroughness of the scale development procedure and their validities. Moreover, not only justifying why the development of a new scale is necessary, but also improving the quality of the existing scales by doing multiple iterations is significant in the future. Likewise, the inclusion of all the dimensions of ISA, while generating the initial items pool is an important aspect to be considered. A thorough discussion, recommendations for future research, conclusions, and study limitations are provided. Elsevier 2023-03-05 /pmc/articles/PMC10015252/ /pubmed/36938452 http://dx.doi.org/10.1016/j.heliyon.2023.e14234 Text en © 2023 The Authors https://creativecommons.org/licenses/by/4.0/This is an open access article under the CC BY license (http://creativecommons.org/licenses/by/4.0/).
spellingShingle Research Article
Rohan, Rohani
Pal, Debajyoti
Hautamäki, Jari
Funilkul, Suree
Chutimaskul, Wichian
Thapliyal, Himanshu
A systematic literature review of cybersecurity scales assessing information security awareness
title A systematic literature review of cybersecurity scales assessing information security awareness
title_full A systematic literature review of cybersecurity scales assessing information security awareness
title_fullStr A systematic literature review of cybersecurity scales assessing information security awareness
title_full_unstemmed A systematic literature review of cybersecurity scales assessing information security awareness
title_short A systematic literature review of cybersecurity scales assessing information security awareness
title_sort systematic literature review of cybersecurity scales assessing information security awareness
topic Research Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10015252/
https://www.ncbi.nlm.nih.gov/pubmed/36938452
http://dx.doi.org/10.1016/j.heliyon.2023.e14234
work_keys_str_mv AT rohanrohani asystematicliteraturereviewofcybersecurityscalesassessinginformationsecurityawareness
AT paldebajyoti asystematicliteraturereviewofcybersecurityscalesassessinginformationsecurityawareness
AT hautamakijari asystematicliteraturereviewofcybersecurityscalesassessinginformationsecurityawareness
AT funilkulsuree asystematicliteraturereviewofcybersecurityscalesassessinginformationsecurityawareness
AT chutimaskulwichian asystematicliteraturereviewofcybersecurityscalesassessinginformationsecurityawareness
AT thapliyalhimanshu asystematicliteraturereviewofcybersecurityscalesassessinginformationsecurityawareness
AT rohanrohani systematicliteraturereviewofcybersecurityscalesassessinginformationsecurityawareness
AT paldebajyoti systematicliteraturereviewofcybersecurityscalesassessinginformationsecurityawareness
AT hautamakijari systematicliteraturereviewofcybersecurityscalesassessinginformationsecurityawareness
AT funilkulsuree systematicliteraturereviewofcybersecurityscalesassessinginformationsecurityawareness
AT chutimaskulwichian systematicliteraturereviewofcybersecurityscalesassessinginformationsecurityawareness
AT thapliyalhimanshu systematicliteraturereviewofcybersecurityscalesassessinginformationsecurityawareness