Companies, public authorities, and private Internet users are increasingly confronted with cyber risks. However, research and practice have focused particularly on cyber security in an organizational context. This ignores the fact that private individuals face cyber risks that differ from those they encounter as part of their job profile in an organizational context. Moreover, it is evident that private individuals behave differently concerning cyber risks, which can be explained by different context-dependent threat awareness as part of multi-dimensional cyber security competencies. Therefore, we extend the Cyber Security Domain Model (CSDM), which was initially established as the prerequisite for building cyber security competencies related to threats within an organizational context, to individuals. We draw on practitioner as well as academic sources to adjust and refine the two dimensions of (1) threat area and (2) threat event in the context of individuals, using a structured literature review.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

How to Strengthen Personal Cyber Security Competencies? Extending the Cyber Security Domain Model (CSDM) to Individuals: A Literature-Based Domain Analysis

  • Florian Schütz,
  • Laura Scholz,
  • Simon Hugenberg,
  • Julia Warwas,
  • Simon Trang

摘要

Companies, public authorities, and private Internet users are increasingly confronted with cyber risks. However, research and practice have focused particularly on cyber security in an organizational context. This ignores the fact that private individuals face cyber risks that differ from those they encounter as part of their job profile in an organizational context. Moreover, it is evident that private individuals behave differently concerning cyber risks, which can be explained by different context-dependent threat awareness as part of multi-dimensional cyber security competencies. Therefore, we extend the Cyber Security Domain Model (CSDM), which was initially established as the prerequisite for building cyber security competencies related to threats within an organizational context, to individuals. We draw on practitioner as well as academic sources to adjust and refine the two dimensions of (1) threat area and (2) threat event in the context of individuals, using a structured literature review.