Evolution of information security awareness towards maturity: a systematic review

This systematic review provides an in-depth analysis of existing information security awareness (ISA) maturity models. This review synthesizes findings from 25 scholarly articles, identifying standard dimensions such as risk management, organizational culture, training programs, policy compliance, a...

Full description

Bibliographic Details
Main Authors: Ahmad, Mohd Ridzam, Osman, Mohd Hafeez, Abdullah, Azizol, Sharif, Khaironi Yatim
Format: Article
Language:English
Published: Insight Society 2024
Online Access:http://psasir.upm.edu.my/id/eprint/118994/
http://psasir.upm.edu.my/id/eprint/118994/1/118994.pdf
_version_ 1848867843772252160
author Ahmad, Mohd Ridzam
Osman, Mohd Hafeez
Abdullah, Azizol
Sharif, Khaironi Yatim
author_facet Ahmad, Mohd Ridzam
Osman, Mohd Hafeez
Abdullah, Azizol
Sharif, Khaironi Yatim
author_sort Ahmad, Mohd Ridzam
building UPM Institutional Repository
collection Online Access
description This systematic review provides an in-depth analysis of existing information security awareness (ISA) maturity models. This review synthesizes findings from 25 scholarly articles, identifying standard dimensions such as risk management, organizational culture, training programs, policy compliance, and technical measures. Despite diverse approaches, significant gaps are evident, particularly the absence of tailored models for specific organizational types like public sector entities. Additionally, the reliance on self-reported data and expert opinions in many models introduces biases, limiting their applicability. The findings underscore the need for organizations to adopt a comprehensive approach to ISA maturity, combining technical controls with behavioral assessments. This holistic view is essential for developing robust ISA maturity frameworks to address evolving cyber threats. Emphasizing compliance with established standards, such as ISO/IEC 27001, is critical to enhancing ISA across industries. Future research should focus on validating and refining ISA maturity models in diverse contexts and industries. This includes testing models in different organizational settings to ensure broader applicability and developing frameworks integrating technical and behavioral dimensions. Addressing sector-specific tailoring, integrating technical and managerial aspects, and providing rigorous empirical validation are critical for developing more effective and adaptable models. Developing ISA maturity models specifically tailored for the public sector is vital due to these organizations’ unique challenges and responsibilities. Utilizing updated versions of standards like ISO 27000 series provides a robust framework for maintaining high information security awareness and preparedness standards. © (2024), (Insight Society Insight Society). All rights reserved.
first_indexed 2025-11-15T14:42:56Z
format Article
id upm-118994
institution Universiti Putra Malaysia
institution_category Local University
language English
last_indexed 2025-11-15T14:42:56Z
publishDate 2024
publisher Insight Society
recordtype eprints
repository_type Digital Repository
spelling upm-1189942025-08-01T02:02:28Z http://psasir.upm.edu.my/id/eprint/118994/ Evolution of information security awareness towards maturity: a systematic review Ahmad, Mohd Ridzam Osman, Mohd Hafeez Abdullah, Azizol Sharif, Khaironi Yatim This systematic review provides an in-depth analysis of existing information security awareness (ISA) maturity models. This review synthesizes findings from 25 scholarly articles, identifying standard dimensions such as risk management, organizational culture, training programs, policy compliance, and technical measures. Despite diverse approaches, significant gaps are evident, particularly the absence of tailored models for specific organizational types like public sector entities. Additionally, the reliance on self-reported data and expert opinions in many models introduces biases, limiting their applicability. The findings underscore the need for organizations to adopt a comprehensive approach to ISA maturity, combining technical controls with behavioral assessments. This holistic view is essential for developing robust ISA maturity frameworks to address evolving cyber threats. Emphasizing compliance with established standards, such as ISO/IEC 27001, is critical to enhancing ISA across industries. Future research should focus on validating and refining ISA maturity models in diverse contexts and industries. This includes testing models in different organizational settings to ensure broader applicability and developing frameworks integrating technical and behavioral dimensions. Addressing sector-specific tailoring, integrating technical and managerial aspects, and providing rigorous empirical validation are critical for developing more effective and adaptable models. Developing ISA maturity models specifically tailored for the public sector is vital due to these organizations’ unique challenges and responsibilities. Utilizing updated versions of standards like ISO 27000 series provides a robust framework for maintaining high information security awareness and preparedness standards. © (2024), (Insight Society Insight Society). All rights reserved. Insight Society 2024 Article PeerReviewed text en http://psasir.upm.edu.my/id/eprint/118994/1/118994.pdf Ahmad, Mohd Ridzam and Osman, Mohd Hafeez and Abdullah, Azizol and Sharif, Khaironi Yatim (2024) Evolution of information security awareness towards maturity: a systematic review. International Journal on Advanced Science, Engineering and Information Technology, 14 (5). pp. 1738-1747. ISSN 2088-5334; eISSN: 2460-6952 https://ijaseit.insightsociety.org/index.php/ijaseit/article/view/20234 10.18517/ijaseit.14.5.20234
spellingShingle Ahmad, Mohd Ridzam
Osman, Mohd Hafeez
Abdullah, Azizol
Sharif, Khaironi Yatim
Evolution of information security awareness towards maturity: a systematic review
title Evolution of information security awareness towards maturity: a systematic review
title_full Evolution of information security awareness towards maturity: a systematic review
title_fullStr Evolution of information security awareness towards maturity: a systematic review
title_full_unstemmed Evolution of information security awareness towards maturity: a systematic review
title_short Evolution of information security awareness towards maturity: a systematic review
title_sort evolution of information security awareness towards maturity: a systematic review
url http://psasir.upm.edu.my/id/eprint/118994/
http://psasir.upm.edu.my/id/eprint/118994/
http://psasir.upm.edu.my/id/eprint/118994/
http://psasir.upm.edu.my/id/eprint/118994/1/118994.pdf