A Coherence Model to Outline Obstacles and Success Factors for Information Security from the CISO's Point of View
Abstract
Against the backdrop of the progressive digitalization of Critical Infrastructures (CRITIS), especially within the socio-technical fields, this paper addresses the identification of obstacles as well as critical, technical, and human success factors, which play an essential role in efficient information security management. Furthermore, the focus is also put on the crystallization of differentiated views regarding the meaningfulness and usefulness of laws. To this end, we conducted a study with 86 chief information security officers, including CRITIS with 76% participation and non-CRITIS with 24% participation, data center operators (14), water and wastewater utilities (25), energy supply companies (33), and healthcare stakeholders (14) in Germany. The study is based on a methodological pluralistic orientation in which, in addition to the integration of quantitative methods for empirical data collection, other analytical approaches are used to determine coherence and correlation. As an artifact, the empirically validated factors are compiled intersectoral in a coherence model and related in terms of causality.
Keywords: information security obstacles, information security success factors, information security management system, coherence analysis, ISMS, CRITIS, CISO
DOI: 10.54941/ahfe1002206
Cite this paper
More from this volume
- A Metric to Assist in Detecting International Phishing or Ransomware Cyberattacks
- Insider Threat: Cognitive Effects of Modern Apathy towards Privacy, Trust, and Security
- A Didactic Tool for Digital Forensics
- A Closer Look at Insider Threat Research
- Social Engineering and Human-Robot Interactions' Risks
- Isolating Key Phrases to Identify Ransomware Attackers
- Information Security Awareness and Training as a Holistic Key Factor – How Can a Human Firewall Take on a Complementary Role in Information Security?
- Cyberdefense Adaptive Training Based on the Classification of Operator Cognitive State
- Exploring Human and Environmental Factors that Make Organizations Resilient to Social Engineering Attacks
- Assessing Human Factors and Cyber Attacks at the Human-Machine Interface: Threats to Safety and Pilot and Controller Performance
- Navigating through Cyber Threats, A Maritime Navigator’s Experience
- Privacy Concerns about Smart Home Devices: A Comparative Analysis between Non-Users and Users


AHFE Open Access