A holistic framework for the fostering of an information security sub-culture in organizations
نویسندگان
چکیده
Modern businesses operates in an emerging global information society. In this information society it is imperative for modern organizations to take the protection of their information resources seriously. This protection of information resources is to a large extent dependent on human co-operated behavior. This human factor is the weakest link in information security, and consists of two interrelated dimensions. Firstly, employees must have sufficient knowledge about information security in order to effectively implement, and maintain, the various information security controls. Secondly, the employees must have the correct attitude towards information security. These two dimensions to the human factor in information security are closely related, and to a degree co-dependent upon each other. It would thus make sense to address these dimensions holistically. This paper combines previously proposed principles and methodologies into a single holistic framework that addresses both the dimensions to this human factor in information security.
منابع مشابه
Fostering Information Security Culture in Small and Medium Size Enterprises: An Interpretive Study in Australia
By having an effective organisational information security culture where employees intuitively protect corporate information assets, small and medium size enterprises (SMEs) could improve information security. However, previous research has largely overlooked the development of such a culture for SMEs, and the national context in which SMEs operate. The paper explores this topic and provides ke...
متن کاملInformation Security Subcultures of Professional Groups in Organizations: A Conceptual Framework Abstract
The need for a strong security culture in organizations has been emphasized by many researchers. Cultures in some organizations are known to be differentiated, i.e., there may be variations in cultures across professional groups within a single organization. The (sub)culture of a professional group in an organization is influenced by many factors. In the current article, we propose a theory-bas...
متن کاملExploring the Type of Relationship between Information Security Management and Organizational Culture (Case Study in TAM Iran Khodro Co.)
A culture conducive to information security practice is extremely important for organizations since information has to be critical assets in modern enterprises. Thus for understanding and improving the organizational behavior with regard to information security, enterprises may look into organizational culture and examine how it affects the effectiveness of implementing ISM. This study aims ...
متن کاملExploring the Type of Relationship between Information Security Management and Organizational Culture (Case Study in TAM Iran Khodro Co.)
A culture conducive to information security practice is extremely important for organizations since information has to be critical assets in modern enterprises. Thus for understanding and improving the organizational behavior with regard to information security, enterprises may look into organizational culture and examine how it affects the effectiveness of implementing ISM. This study aims ...
متن کاملExamine the components of organizational agility to design a framework for achieving agility in social security organization
Background and purpose: The purpose of the study was to examine the dimensions and components of organizational agility to design a framework. Materials and methods: The methodology is descriptive. The statistical society was selected from employees in the Social Security organization of Bojnourd (N=148). The samples were 132 staff that return the questionaries. The data collected by a researc...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2005