Designing and Evaluating a Role-Based Competency Assessment Dashboard for Privacy and Information Security Training in Government
收藏资源简介:
Background: The increasing reliance on digital systems in government has amplified the need for effective governance of privacy and information security, particularly in regulatory contexts shaped by data protection and cybersecurity legislation. Although public-sector organizations are subject to comprehensive legal and normative frameworks, they often lack practical mechanisms to translate these obligations into role-specific competencies and actionable training strategies, resulting in persistent gaps between formal compliance requirements and organizational capabilities. Aims: This study aims to design and empirically evaluate a structured, role-based approach to assessing and prioritizing competencies for privacy and information security governance in public-sector organizations. Method: We designed a competency assessment dashboard grounded in a systematic analysis of legal, regulatory, and technical documents. The artifact defines key organizational roles and associated competencies structured across five proficiency levels and integrates a weighted decision model based on the Analytic Hierarchy Process (AHP). The dashboard was evaluated through expert validation and two practitioner surveys conducted with professionals working in Brazilian federal public administration, covering both privacy and information security contexts.Results: Survey results indicate that practitioners perceive the proposed dashboard as useful, coherent, and appropriate for diagnosing role-specific competency gaps and guiding training prioritization. High levels of agreement were observed regarding the adequacy of the defined competencies, the usefulness of proficiency levels, the fairness of the AHP-based weighting scheme, and the acceptability of the adopted assessment threshold, supporting the applicability of the artifact in real organizational settings. Conclusions: By operationalizing regulatory requirements into a practical, competency-based assessment mechanism, this study contributes a reusable artifact to support structured training journeys for privacy and information security in government. The findings provide empirical evidence of practitioners’ acceptance of the approach and highlight its potential to improve capacity building, transparency, and governance effectiveness in software-intensive public-sector organizations.



