Prior industry surveys and research studies have revealed that organizational security awareness programs may face a number of challenges, including lack of: leadership support; resources; and staff with sufficient background and skills to implement an effective and engaging program. However, no prior research has explored security awareness programs specifically in the United States (U.S.) government (federal) sector. To address this gap, NIST conducted a two-phase, mixed methods research study to understand the needs, challenges, and practices of federal security awareness programs. This report describes the research background and methodology, along with the characteristics of the participants, organizations, and programs represented in the study. Research results can serve as a resource for federal security awareness professionals, managers, and organizational decision makers to improve and advocate for their organizations' security awareness programs. Results can also inform the development of federal security awareness guidance, policies, sharing forums, and initiatives meant to aid programs in becoming more effective. While focused on the U.S. government, findings may also have implications for organizational security awareness programs in other sectors.
Document Citations
Citations are generated automatically from bibliographic data
as a convenience and may not be complete or accurate.
Chicago
National Institute of Standards and Technology (NIST), Commerce Department. "Federal Cybersecurity Awareness Programs: A Mixed Methods Research Study". Government. Commerce Department, March 25, 2022. https://www.govinfo.gov/app/details/GOVPUB-C13-d84101065d68495bee26dddf3a6dc5b5
APA
National Institute of Standards and Technology (NIST), Commerce Department. (2022, March 25). Federal Cybersecurity Awareness Programs: A Mixed Methods Research Study. [Government]. Commerce Department. https://www.govinfo.gov/app/details/GOVPUB-C13-d84101065d68495bee26dddf3a6dc5b5
MLA
National Institute of Standards and Technology (NIST), Commerce Department. Federal Cybersecurity Awareness Programs: A Mixed Methods Research Study. Commerce Department, (25 Mar 2022), https://www.govinfo.gov/app/details/GOVPUB-C13-d84101065d68495bee26dddf3a6dc5b5
Bluebook
National Institute of Standards and Technology (NIST), Commerce Department, Federal Cybersecurity Awareness Programs, GovInfo, (March 25, 2022), https://www.govinfo.gov/app/details/GOVPUB-C13-d84101065d68495bee26dddf3a6dc5b5