earticle

논문검색

Cultivating and Assessing an Organizational Information Security Culture; an Empirical Study

원문정보

초록

영어

An information security-aware culture will minimize internal threats to information assets through the construction of appropriate information security beliefs and values that guide employee behavior when interacting with information assets and information technology systems. This paper aims to illustrate the application of the Information Security Culture Framework (ISCF) to asses and cultivate an information security aware culture within an organization through an empirical study. The ISCF is a comprehensive framework that consists of five dimensions (Strategy, Technology, Organization, People, and Environment) and integrates change management and the human factor in information security. The empirical study includes three case studies, selected to demonstrate the effectiveness of ISCF in describing and explaining the organizational information security culture. A sequential mixed method, to collect quantitative survey data and qualitative interview data, is used to demonstrate the validity and reliability of the framework. The ISCF therefore could be used by all types of organizations in order to assess whether an acceptable level of information security culture has been implemented and, if not, corrective actions are suggested.

목차

Abstract
 1. Introduction
  1.1 Information Security Culture
  1.2 Literature Review
  1.3 The presented work
 2. Methodology
  2.1 Data Gathering
 3. Results and Analysis
  3.1 Questionnaire Results
 4.1 Interview Results
 5. Discussion
 6. Conclusion
 References

저자정보

  • Areej Al Hogail Department of Information Systems College of Computing and Information Sciences King Saud University

참고문헌

자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

      0개의 논문이 장바구니에 담겼습니다.