{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,5]],"date-time":"2026-07-05T11:18:50Z","timestamp":1783250330147,"version":"3.54.6"},"reference-count":98,"publisher":"Informa UK Limited","issue":"3","funder":[{"name":"European Union\u2019s Horizon 2020 research"},{"name":"innovation program","award":["832907"],"award-info":[{"award-number":["832907"]}]}],"content-domain":{"domain":["www.tandfonline.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Information Systems"],"published-print":{"date-parts":[[2022,5,4]]},"DOI":"10.1080\/08874417.2020.1845583","type":"journal-article","created":{"date-parts":[[2020,11,23]],"date-time":"2020-11-23T22:35:24Z","timestamp":1606170924000},"page":"452-462","update-policy":"https:\/\/doi.org\/10.1080\/tandf_crossmark_01","source":"Crossref","is-referenced-by-count":66,"title":["A Cyber-Security Culture Framework for Assessing Organization Readiness"],"prefix":"10.1080","volume":"62","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0078-6969","authenticated-orcid":false,"given":"Anna","family":"Georgiadou","sequence":"first","affiliation":[{"name":"National Technical University of Athens, Athens, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9616-447X","authenticated-orcid":false,"given":"Spiros","family":"Mouzakitis","sequence":"additional","affiliation":[{"name":"National Technical University of Athens, Athens, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0577-2988","authenticated-orcid":false,"given":"Kanaris","family":"Bounas","sequence":"additional","affiliation":[{"name":"National Technical University of Athens, Athens, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2618-5715","authenticated-orcid":false,"given":"Dimitrios","family":"Askounis","sequence":"additional","affiliation":[{"name":"National Technical University of Athens, Athens, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"301","published-online":{"date-parts":[[2020,11,23]]},"reference":[{"key":"cit0001","volume-title":"The history of information security: A comprehensive handbook","author":"Leeuw KD","year":"2007"},{"key":"cit0002","doi-asserted-by":"publisher","DOI":"10.1016\/S0167-4048(03)00407-3"},{"issue":"7","key":"cit0003","doi-asserted-by":"crossref","first-page":"615","DOI":"10.1016\/S0167-4048(00)07021-8","volume":"19","author":"Solms BV","year":"2000","journal-title":"Comput Sec"},{"key":"cit0004","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-15257-3_1"},{"key":"cit0005","doi-asserted-by":"publisher","DOI":"10.1080\/10580530701586136"},{"key":"cit0006","doi-asserted-by":"publisher","DOI":"10.4018\/irmj.2005100102"},{"key":"cit0007","doi-asserted-by":"publisher","DOI":"10.1080\/19393555.2012.747234"},{"key":"cit0008","doi-asserted-by":"publisher","DOI":"10.1201\/1078\/43192.17.3.20000601\/31239.6"},{"key":"cit0009","volume-title":"7th Australian Information Security Management Conference","author":"Williams P","year":"2009"},{"key":"cit0010","unstructured":"Business and Advisory Committee to the OECD, Securing your business. An companion for small or entrepreneurial companies to the 2002 OECD guidelines for the security of networks and information systems:Towards a culture of security. International Chamber of Commerce: OECD. 2004."},{"key":"cit0011","doi-asserted-by":"publisher","DOI":"10.2307\/2392246"},{"key":"cit0012","doi-asserted-by":"publisher","DOI":"10.1146\/annurev.so.11.080185.002325"},{"key":"cit0013","volume-title":"Diagnosing and changing organizational culture: based on the competing values framework","author":"Cameron KS","year":"2011"},{"key":"cit0014","doi-asserted-by":"publisher","DOI":"10.1016\/j.leaqua.2005.12.001"},{"key":"cit0015","doi-asserted-by":"publisher","DOI":"10.1287\/orsc.5.3.309"},{"key":"cit0016","doi-asserted-by":"publisher","DOI":"10.1108\/0885862031047313"},{"key":"cit0017","doi-asserted-by":"publisher","DOI":"10.1057\/ejis.2009.6"},{"key":"cit0018","doi-asserted-by":"publisher","DOI":"10.2307\/25750690"},{"key":"cit0019","doi-asserted-by":"publisher","DOI":"10.1287\/isre.1.3.255"},{"key":"cit0020","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2015.11.001"},{"key":"cit0021","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-115"},{"key":"cit0022","doi-asserted-by":"publisher","DOI":"10.4018\/978-1-4666-0179-6"},{"key":"cit0023","unstructured":"Ronald RS. Recommended security controls for federal information systems and organizations. Special Publication (NIST SP) - 800-53 Rev 3. 2009."},{"key":"cit0024","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2012.49"},{"key":"cit0025","doi-asserted-by":"publisher","DOI":"10.1108\/MRR-04-2013-0085"},{"key":"cit0026","first-page":"133","author":"Siponen M","year":"2007","journal-title":"Privacy Trust Complex Environ"},{"key":"cit0027","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2007.206"},{"key":"cit0028","doi-asserted-by":"publisher","DOI":"10.1016\/j.chb.2008.04.005"},{"key":"cit0029","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2008.11.010"},{"key":"cit0030","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2009.05.008"},{"key":"cit0031","doi-asserted-by":"publisher","DOI":"10.17705\/1jais.00030"},{"key":"cit0032","doi-asserted-by":"publisher","DOI":"10.1080\/15332861.2010.487415"},{"key":"cit0033","doi-asserted-by":"publisher","DOI":"10.1111\/j.1540-5915.2012.00361.x"},{"key":"cit0034","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2012.09.010"},{"key":"cit0035","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijinfomgt.2015.11.009"},{"key":"cit0036","unstructured":"ISO\/IEC. ISO\/IEC 27002:2013(E) Information technology \u2014 security techniques \u2014 code of practice for information security controls. International Organization for Standardization (ISO). 2013."},{"key":"cit0037","unstructured":"ISO\/IEC. ISO\/IEC 27001. Information security management. International Organization for Standardization (ISO). 2015."},{"key":"cit0038","unstructured":"Information Systems Audit and Control Association (ISACA). COBIT5: a business framework for the governance and management of enterprise IT. 2012."},{"key":"cit0039","doi-asserted-by":"publisher","DOI":"10.1016\/S1361-3723(05)70275-X"},{"key":"cit0040","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-53r4"},{"key":"cit0041","unstructured":"ENISA. Cyber security culture in organisations. European Union Agency For Network and Information Security. 2017."},{"key":"cit0042","volume-title":"To measure security culture: A scientific approach","author":"Petric G","year":"2018"},{"key":"cit0043","unstructured":"Energy shield. [Online]. 2019 [accessed 2020 Mar 25]. https:\/\/energy-shield.eu\/."},{"key":"cit0044","volume-title":"CIS controls","author":"CIS","year":"2019"},{"key":"cit0045","unstructured":"All Hazards Consortium (AHC). Cyber security risk mitigation checklist. [Online]. [accessed 2019 Oct 7]. https:\/\/www.ahcusa.org\/uploads\/2\/1\/9\/8\/21985670\/cybersecurityriskmitigationchecklist.pdf."},{"key":"cit0046","unstructured":"Utah Governement. Cyber Security Controls Checklist."},{"key":"cit0047","unstructured":"Cybersecurity checklist series. JMARK Business Solutions."},{"key":"cit0048","unstructured":"ENISA. The new users\u2019 guide: how to raise information security awareness. [Online]. 2010 [accessed 2019 Oct 24]. https:\/\/www.enisa.europa.eu\/publications\/archive\/copy_of_new-users-guide."},{"key":"cit0049","unstructured":"Bernik I, Prislan K. Measuring information security performance with 10 by 10 model for holistic state evaluation. [accessed 2016 Sep 21]."},{"key":"cit0050","doi-asserted-by":"publisher","DOI":"10.1016\/S0167-4048(03)00007-5"},{"key":"cit0051","doi-asserted-by":"publisher","DOI":"10.1016\/S1361-3723(12)70053-2"},{"key":"cit0052","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2012.04.004"},{"key":"cit0053","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2006.10.008"},{"key":"cit0054","volume-title":"Proceedings of the 25th Australasian Conference on Information Systems","author":"Alshaikh M","year":"2014"},{"key":"cit0055","volume-title":"Sixth Pacific Asia Conference on Information Systems","author":"Chia P","year":"2002"},{"key":"cit0056","volume-title":"Proceedings of the 3rd Australian Information Security Management Conference","author":"Ngo L","year":"2005"},{"key":"cit0057","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2004.01.012"},{"key":"cit0058","volume-title":"Building a practical information security program","author":"Andress J","year":"2016"},{"key":"cit0059","unstructured":"RiskWatch. Cyber security assessment checklist. Risk Management Software Solutions."},{"key":"cit0060","unstructured":"ITU. Global cybersecurity index. [Online]. [accessed 2019 Oct 2]. https:\/\/www.itu.int\/en\/ITU-D\/Cybersecurity\/Pages\/global-cybersecurity-index.aspx."},{"key":"cit0061","volume-title":"People-centric security: transforming your enterprise security culture","author":"Hayden L","year":"2015"},{"key":"cit0062","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2009.09.002"},{"key":"cit0063","doi-asserted-by":"publisher","DOI":"10.1016\/S2212-5671(15)00091-X"},{"key":"cit0064","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2009.07.001"},{"key":"cit0065","doi-asserted-by":"publisher","DOI":"10.1016\/S1361-3723(06)70430-4"},{"key":"cit0066","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2004.01.013"},{"key":"cit0067","volume-title":"Measuring and evaluating an effective security culture","author":"CISCO","year":"2007"},{"key":"cit0068","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.12.006"},{"key":"cit0069","volume-title":"Pacific Asia Conference on Information Systems","author":"Lim J","year":"2010"},{"key":"cit0070","doi-asserted-by":"publisher","DOI":"10.4018\/978-1-4666-0197-0.ch017"},{"key":"cit0071","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2015.05.012"},{"key":"cit0072","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2009.02.005"},{"key":"cit0073","unstructured":"Laycock A, Petric G, Roer K. The seven dimensions of security culture. Oslo (Norway): CLTRe AS. 2019."},{"key":"cit0074","unstructured":"CPNI (Centre for the Protection of National Infrastructure). Introduction to SeCuRE 4. CPNI. 2018."},{"key":"cit0075","unstructured":"Employee survey questions. [Online]. [accessed 2019 Oct 11]. https:\/\/hr-survey.com\/EmployeeSurveyQuestions.htm."},{"key":"cit0076","doi-asserted-by":"publisher","DOI":"10.1108\/09685221011095254"},{"key":"cit0077","doi-asserted-by":"publisher","DOI":"10.1145\/3011141.3011165"},{"key":"cit0078","volume":"88","author":"Wiley A","year":"2020","journal-title":"Comput Sec"},{"key":"cit0079","volume-title":"ISSA 2005 New Knowledge Today Conference","author":"Van Niekerk J","year":"2005"},{"key":"cit0080","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.05.002"},{"key":"cit0081","volume-title":"Proceedings of the 8th European Conference on Information Management and Evaluation, ECIME 2014","author":"Da Veiga A","year":"2014"},{"key":"cit0082","doi-asserted-by":"publisher","DOI":"10.1108\/ICS-12-2015-0048"},{"key":"cit0083","unstructured":"CPNI (Centre for the Protection of National Infrastructure). Introduction to security. 2015."},{"key":"cit0084","unstructured":"SANS. Level-up test. SANS. [Online]. https:\/\/www.sans.org\/level-up\/test.html."},{"key":"cit0085","doi-asserted-by":"publisher","DOI":"10.1080\/0144929X.2012.708787"},{"key":"cit0086","doi-asserted-by":"publisher","DOI":"10.1016\/0377-2217(90)90057-I"},{"key":"cit0087","doi-asserted-by":"publisher","DOI":"10.1016\/0377-2217(86)90044-5"},{"key":"cit0088","doi-asserted-by":"publisher","DOI":"10.1016\/0377-2217(86)90054-8"},{"key":"cit0089","doi-asserted-by":"publisher","DOI":"10.1016\/S0377-2217(03)00020-1"},{"key":"cit0090","unstructured":"The European Parliament and the Council of the European Union. 2018 reform of EU data protection rule. 2018 May 25. [Online]. [accessed 2020 Mar 26]. https:\/\/gdpr-info.eu\/."},{"key":"cit0091","unstructured":"The European Parliament and the Council of the European Union. EUR-Lex- 32016L1148 - EN - EUR-Lex. 2016 Jun 7. [Online]. [accessed 2020 Mar 26]. https:\/\/eur-lex.europa.eu\/eli\/dir\/2016\/1148\/oj."},{"key":"cit0092","unstructured":"European Commission. The directive on security of network and information systems (NIS Directive). European Commission. [Online]. [accessed 2020 Mar 26]. https:\/\/ec.europa.eu\/digital-single-market\/en\/network-and-information-security-nis-directive."},{"key":"cit0093","volume-title":"4th International Conference on Networks and Security (NSEC 2020)","author":"Georgiadou A","year":"2020"},{"key":"cit0094","doi-asserted-by":"crossref","unstructured":"Georgiadou A, Mouzakitis S, Askounis D. Working from home during COVID-19 crisis \u2013 A cyber-security culture assessment survey. Mendeley Data. Athens. 2020.","DOI":"10.1057\/s41284-021-00286-2"},{"key":"cit0095","volume-title":"The 2005 International Conference on Security and Management","author":"Gathegi J","year":"2005"},{"key":"cit0096","unstructured":"ENISA. Cybersecurity culture guidelines: behavioural aspects of cybersecurity. European Union Agency for Network and Information Security. 2018."},{"key":"cit0097","unstructured":"Da Veiga A, Martins N, Eloff JHP. Information security culture\u2013validation of an assessment instrument. South. African Bus. Rev. 2007;11(1):146\u2013166."},{"key":"cit0098","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-50"}],"container-title":["Journal of Computer Information Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.tandfonline.com\/doi\/pdf\/10.1080\/08874417.2020.1845583","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,4,29]],"date-time":"2022-04-29T17:12:37Z","timestamp":1651252357000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.tandfonline.com\/doi\/full\/10.1080\/08874417.2020.1845583"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,11,23]]},"references-count":98,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2022,5,4]]}},"alternative-id":["10.1080\/08874417.2020.1845583"],"URL":"https:\/\/doi.org\/10.1080\/08874417.2020.1845583","relation":{},"ISSN":["0887-4417","2380-2057"],"issn-type":[{"value":"0887-4417","type":"print"},{"value":"2380-2057","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,11,23]]},"assertion":[{"value":"The publishing and review policy for this title is described in its Aims & Scope.","order":1,"name":"peerreview_statement","label":"Peer Review Statement"},{"value":"http:\/\/www.tandfonline.com\/action\/journalInformation?show=aimsScope&journalCode=ucis20","URL":"http:\/\/www.tandfonline.com\/action\/journalInformation?show=aimsScope&journalCode=ucis20","order":2,"name":"aims_and_scope_url","label":"Aim & Scope"},{"value":"2020-11-23","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}