An Integrated Model of Organizational Cyber Resilience: The ‎Role of Cybersecurity Management, Employee Awareness, ‎Incident Response, and Business Continuity

سال انتشار: 1405
نوع سند: مقاله کنفرانسی
زبان: فارسی
مشاهده: 21

فایل این مقاله در 15 صفحه با فرمت PDF و WORD قابل دریافت می باشد

استخراج به نرم افزارهای پژوهشی:

لینک ثابت به این مقاله:

شناسه ملی سند علمی:

ICMHSR24_159

تاریخ نمایه سازی: 23 شهریور 1405

چکیده مقاله:

The dependence of organizations on digital technologies has expanded their exposure to ‎cybersecurity threats. Cyber incidents can compromise information assets, disrupt operations, ‎generate financial losses, and undermine organizational continuity. Therefore, cybersecurity ‎should no longer be viewed solely as a technical function focused on preventing attacks. ‎Organizations also need the capability to anticipate, withstand, respond to, recover from, and ‎adapt to cyber disruptions. This study proposes an integrated model of organizational cyber ‎resilience by examining the roles of information security management, cyber risk ‎management, employee cybersecurity awareness and training, IT infrastructure security, ‎incident response capability, and business continuity capability.‎ The study adopts a ‎quantitative and explanatory research design. The conceptual framework is grounded in the ‎Resource-Based View and Dynamic Capability Theory, which emphasize the value of ‎organizational resources and the ability to adapt to changing environmental conditions. To ‎demonstrate the proposed analytical framework, a simulated dataset comprising ۳۰۰ ‎observations and ۳۶ measurement items was developed. Partial Least Squares Structural ‎Equation Modeling (PLS-SEM) is proposed to assess the measurement and structural ‎models, including reliability, convergent validity, discriminant validity, collinearity, ‎explanatory power, effect sizes, predictive relevance, direct effects, and mediation.‎ The ‎preliminary simulation-based results indicate positive relationships between information ‎security management, cyber risk management, employee awareness and training, IT ‎infrastructure security, business continuity, and organizational cyber resilience. IT ‎infrastructure security and business continuity appear to be important dimensions of the ‎proposed framework. In contrast, the direct relationship between incident response capability ‎and cyber resilience is comparatively weaker, suggesting that its contribution may depend on ‎recovery and continuity mechanisms.‎ The study contributes to cybersecurity research by ‎integrating managerial, technological, human, and operational capabilities into a unified cyber ‎resilience framework. From a managerial perspective, the proposed model can assist ‎organizations in identifying cybersecurity capability gaps and coordinating investments in ‎prevention, response, recovery, and business continuity.‎

نویسندگان

Mohammad reza Jahan khah

Shiraz Municipality