Cristin-resultat-ID: 2131766
Sist endret: 25. januar 2024, 10:43
NVI-rapporteringsår: 2023
Resultat
Vitenskapelig artikkel
2023

The HORM Diagramming Tool: A Domain-Specific Modelling Tool for SME Cybersecurity Awareness

Bidragsytere:
  • Costas Boletsis
  • Sefat Noor Orni og
  • Ragnhild Halvorsrud

Tidsskrift

VISIGRAPP
ISSN 2184-5921
e-ISSN 2184-4321
NVI-nivå 1

Om resultatet

Vitenskapelig artikkel
Publiseringsår: 2023
Publisert online: 2023
Volum: 3
Sider: 203 - 213
Open Access

Beskrivelse Beskrivelse

Tittel

The HORM Diagramming Tool: A Domain-Specific Modelling Tool for SME Cybersecurity Awareness

Sammendrag

Improving security posture while addressing human errors made by employees are among the most challenging tasks for SMEs concerning cybersecurity risk management. To facilitate these measures, a domain-specific modelling tool for visualising cybersecurity-related user journeys, called the HORM Diagramming Tool (HORM-DT), is introduced. By visualising SMEs’ cybersecurity practices, HORM-DT aims to raise their cybersecurity awareness by highlighting the related gaps, thereby ultimately informing new or updated cyber-risk strategies. HORM-DT’s target group consists of SMEs’ employees with various areas of technical expertise and different backgrounds. The tool was developed as part of the Human and Organisational Risk Modelling (HORM) framework, and the underlying formalism is based on the Customer Journey Modelling Language (CJML) as extended by elements of the CORAS language to cover cybersecurity-related user journeys. HORM-DT is a fork of the open-source Diagrams.net software, which was modified to facilitate the creation of cybersecurity-related diagrams. To evaluate the tool, a usability study following a within-subject design was conducted with 29 participants. HORM-DT achieved a satisfactory system usability scale score of 80.69, and no statistically significant differences were found between participants with diverse diagramming tool experience. The tool’s usability was also praised by participants, although there were negative comments regarding its functionality of connecting elements with lines.

Bidragsytere

Konstantinos Boletsis

Bidragsyterens navn vises på dette resultatet som Costas Boletsis
  • Tilknyttet:
    Forfatter
    ved Sustainable Communication Technologies ved SINTEF AS

Sefat Noor Orni

  • Tilknyttet:
    Forfatter
    ved Institutt for informatikk ved Universitetet i Oslo

Ragnhild Halvorsrud

  • Tilknyttet:
    Forfatter
    ved Sustainable Communication Technologies ved SINTEF AS
1 - 3 av 3