Knowledge of possible cyber threats as well as awareness of appropriate security measures plays a crucial role in the ability of individuals to not only discriminate between an innocuous versus a dangerous cyber event, but more importantly to initiate appropriate cybersecurity behaviors. The purpose of this study was to construct a Cybersecurity Awareness INventory (CAIN) to be used as an instrument to assess users’ cybersecurity knowledge by providing a proficiency score that could be correlated with cyber security behaviors. A scale consisting of 46 items was derived from ISO/IEC 27032. The questionnaire was administered to a sample of college students (N = 277). Based on cybersecurity behaviors reported to the research team by the college’s IT department, each participant was divided into three groups according to the risk reports they received in the past nine months (no risk, low risk, and medium risk). The ANOVA results showed a statistically significant difference in CAIN scores between those in the no risk and medium-risk groups; as expected, CAIN scores were lower in the medium-risk group. The CAIN has the potential to be a useful assessment tool for cyber training programs as well as future studies investigating individuals’ vulnerability to cyberthreats.

The cybersecurity awareness Inventory (CAIN). Early phases of development of a tool for assessing cybersecurity knowledge based on the ISO/IEC 27032 / Tempestini, Giorgia; Rovira, Ericka; Pyke, Aryn; DI NOCERA, Francesco. - In: JOURNAL OF CYBERSECURITY AND PRIVACY. - ISSN 2624-800X. - (2023), pp. 61-75.

The cybersecurity awareness Inventory (CAIN). Early phases of development of a tool for assessing cybersecurity knowledge based on the ISO/IEC 27032

Giorgia Tempestini
Primo
;
Francesco Di Nocera
Ultimo
2023

Abstract

Knowledge of possible cyber threats as well as awareness of appropriate security measures plays a crucial role in the ability of individuals to not only discriminate between an innocuous versus a dangerous cyber event, but more importantly to initiate appropriate cybersecurity behaviors. The purpose of this study was to construct a Cybersecurity Awareness INventory (CAIN) to be used as an instrument to assess users’ cybersecurity knowledge by providing a proficiency score that could be correlated with cyber security behaviors. A scale consisting of 46 items was derived from ISO/IEC 27032. The questionnaire was administered to a sample of college students (N = 277). Based on cybersecurity behaviors reported to the research team by the college’s IT department, each participant was divided into three groups according to the risk reports they received in the past nine months (no risk, low risk, and medium risk). The ANOVA results showed a statistically significant difference in CAIN scores between those in the no risk and medium-risk groups; as expected, CAIN scores were lower in the medium-risk group. The CAIN has the potential to be a useful assessment tool for cyber training programs as well as future studies investigating individuals’ vulnerability to cyberthreats.
2023
cybersecurity; cyber threats; awareness; knowledge; questionnaire; CAIN
01 Pubblicazione su rivista::01a Articolo in rivista
The cybersecurity awareness Inventory (CAIN). Early phases of development of a tool for assessing cybersecurity knowledge based on the ISO/IEC 27032 / Tempestini, Giorgia; Rovira, Ericka; Pyke, Aryn; DI NOCERA, Francesco. - In: JOURNAL OF CYBERSECURITY AND PRIVACY. - ISSN 2624-800X. - (2023), pp. 61-75.
File allegati a questo prodotto
File Dimensione Formato  
Tempestini_The Cybersecurity _2023.pdf

accesso aperto

Tipologia: Versione editoriale (versione pubblicata con il layout dell'editore)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 1.08 MB
Formato Adobe PDF
1.08 MB Adobe PDF

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11573/1671298
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 2
  • ???jsp.display-item.citation.isi??? ND
social impact