LISA: A Scale-Optimized and Psychometrically-Validated Instrument for the Lightweight Assessment of Organizational Information Security Awareness in Heterogeneous Organizations

dc.contributor.authorLanger, David
dc.contributor.authorTolsdorf, Jan
dc.contributor.authorLo Iacono, Luigi
dc.date.accessioned2026-04-22T11:55:23Z
dc.date.issued2026
dc.description.abstractHuman factors are central to an organization’s information security. Information Security Awareness (ISA) is a key construct in behavioral and organizational models explaining employees’ security compliance. However, existing ISA measures often lack theoretical grounding, psychometric rigor, and organizational relevance, or are too lengthy and complex for practical application. These shortcomings hinder empirical testing of behavioral models and the integration of ISA as a variable in organizational research. This paper introduces the Lightweight Information Security Awareness (LISA) scale – the first theory-based, psychometrically validated, and cross-language scale for efficiently assessing ISA in heterogeneous organizational contexts, balancing measurement precision with practical feasibility. Validation involved 1,182 participants from survey panels and 579 employees of a large German university hospital, representing a heterogeneous workforce. LISA demonstrates high internal consistency, measurement invariance across English and German, and strong construct and ecological validity. By correlating LISA with 11 enablers and barriers of organizational information security and differentiating it by a heterogeneous workforce in a hospital context, we demonstrate its ability to support both scientific investigations and practical assessments. LISA provides a quick, reliable, valid, and practical solution for measuring organizational ISA, ultimately offering researchers and practitioners without psychometric expertise a validated tool that is applicable in both behavioral models and everyday organizational environments.
dc.description.sponsorshipSonstige Drittmittelgeber/-innen
dc.identifier.urihttps://jlupub.ub.uni-giessen.de/handle/jlupub/21483
dc.identifier.urihttps://doi.org/10.22029/jlupub-20830
dc.language.isoen
dc.rightsIn Copyright
dc.rights.urihttp://rightsstatements.org/page/InC/1.0/
dc.subjectInformation Security
dc.subjectInformation Security Awareness
dc.subjectPsychometric Validation
dc.subjectPsychometric Scale
dc.subject.ddcddc:004
dc.titleLISA: A Scale-Optimized and Psychometrically-Validated Instrument for the Lightweight Assessment of Organizational Information Security Awareness in Heterogeneous Organizations
dc.typeconferenceObject
local.affiliationFB 07 - Mathematik und Informatik, Physik, Geographie
local.commentAccepted for publication in: 2026 IEEE Symposium on Security and Privacy (SP).
local.projectBMG ZMI1-2521FSB801

Dateien

Originalbündel

Gerade angezeigt 1 - 1 von 1
Lade...
Vorschaubild
Name:
Langer et al. - LISA A Scale-Optimized and Psychometrically-Validated Instrument for the Lightweight Assessment of.pdf
Größe:
403.53 KB
Format:
Adobe Portable Document Format

Lizenzbündel

Gerade angezeigt 1 - 1 von 1
Lade...
Vorschaubild
Name:
license.txt
Größe:
7.58 KB
Format:
Item-specific license agreed upon to submission
Beschreibung: