Initial Plan
Re-read the Security Awareness Campaign overview in the Term Projects project.
Requirements
Develop an initial draft of your security awareness campaign that includes:
- Theme Selection and Justification (15 points)
- Choose a security awareness theme/event from the provided security awareness calendar
- Explain why you selected this particular theme for your target organization
- Discuss its relevance to contemporary security challenges and threat landscape
- Connect your theme choice to current threat intelligence or industry-specific risks
- Target Organization and Audience Analysis (20 points)
- Define your target organization (size, industry, geographic considerations, regulatory environment)
- Analyze the current security culture maturity level using the awareness/behavior/culture framework
- Identify specific audience segments, their roles, risk exposure levels, and existing security knowledge
- Identify specific vulnerabilities (e.g., “Very Attacked People,” high-risk departments, common attack vectors for this audience)
- Define specific, measurable behavioral changes you want to achieve (not just awareness goals)
- Campaign Strategy and Psychology (15 points)
- Explain how your campaign addresses the forgetting curve and incorporates spaced learning principles
- Connect your approach to autonomy/mastery/purpose model – how will your campaign make security personally relevant?
- Describe how you’ll achieve repeated exposure through varied channels and timeframes
- Outline your approach to recognition and positive consequences rather than punitive measures
- Implementation Timeline and Channels (10 points)
- Plan for diverse delivery methods beyond email (consider accessibility and preference differences)
- Detailed implementation schedule (before, during, and after the main event/theme)
- How this campaign connects to broader organizational security objectives and existing programs
- Realistic assessment of what you’ll need to execute this campaign
- Measurement and Success Metrics (15 points)
- Define how you’ll measure actual behavior change (not just completion rates)
- How will you assess whether people feel empowered to report security concerns?
- Plan for measuring belief and attitude changes (surveys, observational indicators)
- Specific, realistic benchmarks that align with your behavioral objectives
- When and how often you’ll assess progress
Deliverable Format: 3-4 page document (PDF or Word) with any preliminary visuals attached
Notes for Success
- Avoid Compliance Theater: Focus on genuine behavior change rather than checkbox completion
- Think Like a Marketer: Consider how to make security the “cupcake” rather than the “broccoli”
- Leverage Real Experience: Draw on your professional knowledge of organizational culture and constraints
- Be Specific: Generic approaches will not be as effective as targeted, contextual strategies
- Plan for Sustainability: Consider how your campaign creates lasting cultural change rather than temporary awareness
Requirements: 3-4 pages

Leave a Reply
You must be logged in to post a comment.