An Organizational Self-Assessment Tool for Digital Security by Design
| Full text | |||
| Source | Journal of Information Systems Security Volume 22, Number 1 (2026)
Pages 61–80
ISSN 1551-0123 (Print)ISSN 1551-0808 (Online) |
||
| Authors | Steven Furnell - University of Nottingham, Nottingham, UK
Maria Bada - Queen Mary University of London, London, UK
Michal Kukula - University of Nottingham, Nottingham, UK
Lucija Šmid - University of Bath, Bath, UK
|
||
| Publisher | Information Institute Publishing, Washington DC, USA | ||
Abstract
Digital Security by Design (DSbD) offers a means to improve IT security by eliminating vulnerabilities often exploited in related attacks. However, the availability of improved technology does not automatically ensure that it will be understood and adopted by potential beneficiaries. Perceptions and priorities may vary within organizations, depending on the role and perspectives of different stakeholders involved in the decision-making. Organizations can benefit from an assessment of their environment, including the extent of stakeholder alignment in understanding and supporting security needs. Building upon prior work that has assessed organizational DSbD awareness, the focus of this paper is a Self-Assessment Tool developed to support the process. A proof-of-concept prototype which enables a demonstration of how data is collected from stakeholders is described, as well as various ways results can be visualized in order to assist the organization to assess its positioning over time. The discussion considers the results of the related evaluation by a group of senior cyber-related stakeholders, identifying areas of support for the concept as well as a range of issues considered for enhancement. The findings support the SAT concept as a means to support the intended objectives, but also highlight the need to consider the extent to which it is compatible with risk assessment frameworks already in use within some organizations. It is also important to ensure that its use and findings are communicated in a manner that is relatable to the stakeholders involved.
Keywords
Digital Security by Design, Self-Assessment Tool, Security Assessment, Stakeholders, Technology Adoption.
References
Braun, V. and Clarke, V. (2006), “Using thematic analysis in psychology,” Qualitative Research in Psychology, 3(2), pp. 77–101.
Dooley, R. (2024), ‘What Is A Chief Executive Officer? CEO Role Explained’, Forbes, www.forbes.com/sites/rogerdooley/article/chief-executive-officer-ceo, 21 April 2024.
DSbD (2024), ‘About Digital Security by Design’, Digital Security by Design. www.dsbd.tech/about/, accessed 25 February 2024.
DSIT (2024), ‘CHERI adoption and diffusion research – Research and analysis’, Department for Science, Innovation and Technology, www.gov.uk/government/publications/cheri-adoption-and-diffusion-research/cheri-adoption-and-diffusionresearch, 15 May 2024.
DSIT (2025), ‘Cyber security breaches survey 2025 - Official Statistics’, Department for Science, Innovation and Technology, 10 April 2025, www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025.
Furnell, S., Bada, M. and Kaberuka, J. (2023), “Assessing Organizational Awareness and Acceptance of Digital Security by Design," Journal of Information Systems Security, 19 (1): 3-19.
Furnell, S., Bada, M. and Kaberuka, J. (2025), “A Self-Assessment Method for Organizational Awareness of Digital Security by Design," Journal of Information Systems Security, 21 (2).
Gartner (nd), ‘Chief Information Officer (CIO)’, www.gartner.com/en/informationtechnology/glossary/cio-chief-information-officer
Lacina, L. (2023), ‘Chief Procurement Officers: What they do and why they’re ‘unsung heroes’ for tackling big global challenges’, World Economic Forum, 19 December 2023. www.weforum.org/stories/2023/12/chief-procurement-officers-what-they-dowhyimportant/
McKinsey and Company (2023), ‘What are the roles and responsibilities of a CFO?’, www.mckinsey.com/featured-insights/mckinsey-explainers/what-are-the-rolesandresponsibilities-of-a-cfo, 29 November 2023.
Straub, D.W. and Welke. R.J. (1998), “Coping with systems risk: Security planning models for management decision making,” MIS Quarterly, 22: 441-469.
Tversky, A. and Kahneman, D. (1974), “Judgment under Uncertainty: Heuristics and Biases,” Science, 185: 1124- 1131.
Vachon, P. (2024), “Security Mismatch,” Communications of the ACM, 67 (2): 40-41.
Woodruff, J., Watson, R.N.M., Chisnall, D., Moore, S.W., Anderson, J., Davis, B., Laurie, B., Neumann, P.G., Norton, R., Roe, M. (2014), ‘The CHERI capability model: Revisiting RISC in an age of risk’, www.cl.cam.ac.uk/research/security/ctsrd/pdfs/201406-isca2014-cheri.pdf .
Woollacott, E. (2024), ‘What Is A Chief Information Security Officer? CISO Explained’, Forbes, www.forbes.com/sites/technology/article/chief-informationsecurity-officer-ciso, 19 March 2024
Yasar, K. and Pratt, M.K. (2022), ‘Definition - chief procurement officer (CPO)’, TechTarget. www.techtarget.com/searchcio/definition/Chief-Procurement-Officer-CPO.
