A holistic framework for the fostering of an information security sub-culture in organizations

نویسندگان

  • Johan Van Niekerk
  • Rossouw von Solms
چکیده

Modern businesses operates in an emerging global information society. In this information society it is imperative for modern organizations to take the protection of their information resources seriously. This protection of information resources is to a large extent dependent on human co-operated behavior. This human factor is the weakest link in information security, and consists of two interrelated dimensions. Firstly, employees must have sufficient knowledge about information security in order to effectively implement, and maintain, the various information security controls. Secondly, the employees must have the correct attitude towards information security. These two dimensions to the human factor in information security are closely related, and to a degree co-dependent upon each other. It would thus make sense to address these dimensions holistically. This paper combines previously proposed principles and methodologies into a single holistic framework that addresses both the dimensions to this human factor in information security.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Fostering Information Security Culture in Small and Medium Size Enterprises: An Interpretive Study in Australia

By having an effective organisational information security culture where employees intuitively protect corporate information assets, small and medium size enterprises (SMEs) could improve information security. However, previous research has largely overlooked the development of such a culture for SMEs, and the national context in which SMEs operate. The paper explores this topic and provides ke...

متن کامل

Information Security Subcultures of Professional Groups in Organizations: A Conceptual Framework Abstract

The need for a strong security culture in organizations has been emphasized by many researchers. Cultures in some organizations are known to be differentiated, i.e., there may be variations in cultures across professional groups within a single organization. The (sub)culture of a professional group in an organization is influenced by many factors. In the current article, we propose a theory-bas...

متن کامل

Exploring the Type of Relationship between Information Security Management and Organizational Culture (Case Study in TAM Iran Khodro Co.)

A culture conducive to information security practice is extremely important for organizations since information has to be critical assets in modern enterprises. Thus for understanding and improving the organizational behavior with regard to information security, enterprises may look into organizational culture and examine how it affects the effectiveness of implementing ISM. This study aims ...

متن کامل

Exploring the Type of Relationship between Information Security Management and Organizational Culture (Case Study in TAM Iran Khodro Co.)

A culture conducive to information security practice is extremely important for organizations since information has to be critical assets in modern enterprises. Thus for understanding and improving the organizational behavior with regard to information security, enterprises may look into organizational culture and examine how it affects the effectiveness of implementing ISM. This study aims ...

متن کامل

Examine the components of organizational agility to design a framework for achieving agility in social security organization

Background and purpose: The purpose of the study was to examine the dimensions and components of organizational agility to design a framework. Materials and methods: The methodology is descriptive. The statistical society was selected from employees in the Social Security organization of Bojnourd (N=148). The samples were 132 staff that return the questionaries.  The data collected by a researc...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2005